Critical Security Flaws Discovered in Go Pay SDK Affecting Multiple Payment Methods
Article Content
- •Two critical vulnerabilities affect all seven payment methods in the Go Pay SDK.
- •CWE-295 allows man-in-the-middle attacks due to disabled TLS verification.
- •CWE-798 exposes sensitive credentials in a public repository.
Two critical vulnerabilities have been identified in the Go Pay SDK, affecting all seven supported payment methods including WeChat, Alipay, and PayPal. The first vulnerability (CWE-295) involves the shared HTTP client globally disabling TLS certificate verification, allowing for potential man-in-the-middle attacks. The second vulnerability (CWE-798) exposes a complete RSA 2048-bit private key along with merchant ID and App ID in a public repository. These flaws could compromise sensitive transaction data and credentials. Developers are advised to revoke the exposed RSA keypair and implement secure coding practices. Affected payment methods include WeChat, Alipay, QQ, and others. The vulnerabilities were disclosed on October 4, 2026, and a full technical report is available upon request.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What are the specific vulnerabilities?
How can I mitigate these vulnerabilities?
Are these vulnerabilities being actively exploited?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…