Skip to content
Critical Security Flaws Discovered in Go Pay SDK Affecting Multiple Payment Methods

Critical Security Flaws Discovered in Go Pay SDK Affecting Multiple Payment Methods

First seen 4 Oct 2026, 21:02 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 22:01 UTC
  • •Two critical vulnerabilities affect all seven payment methods in the Go Pay SDK.
  • •CWE-295 allows man-in-the-middle attacks due to disabled TLS verification.
  • •CWE-798 exposes sensitive credentials in a public repository.

Two critical vulnerabilities have been identified in the Go Pay SDK, affecting all seven supported payment methods including WeChat, Alipay, and PayPal. The first vulnerability (CWE-295) involves the shared HTTP client globally disabling TLS certificate verification, allowing for potential man-in-the-middle attacks. The second vulnerability (CWE-798) exposes a complete RSA 2048-bit private key along with merchant ID and App ID in a public repository. These flaws could compromise sensitive transaction data and credentials. Developers are advised to revoke the exposed RSA keypair and implement secure coding practices. Affected payment methods include WeChat, Alipay, QQ, and others. The vulnerabilities were disclosed on October 4, 2026, and a full technical report is available upon request.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-04
Critical vulnerabilities disclosed
Two critical vulnerabilities affecting multiple payment methods in the Go Pay SDK were reported, including CWE-295 and CWE-798.
github.com

More articles in this cluster (2)

Common questions

What are the specific vulnerabilities?
The vulnerabilities include CWE-295, which disables TLS verification, and CWE-798, which exposes sensitive credentials.
How can I mitigate these vulnerabilities?
Developers should revoke the exposed RSA keypair and ensure TLS verification is enabled in their implementations.
Are these vulnerabilities being actively exploited?
No active exploitation has been reported, but the vulnerabilities pose significant risks.