Skip to content
CVE-2026-105218 in Go-Pay Library Exposes Payment APIs

CVE-2026-105218 in Go-Pay Library Exposes Payment APIs

First seen 4 Oct 2026, 21:02 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 22:01 UTC
  • •CVE-2026-105218 is a critical vulnerability with a CVSS score of 9.1.
  • •The flaw allows man-in-the-middle attacks by disabling TLS certificate verification.
  • •Immediate upgrade to version 1.5.119 or later is recommended to mitigate risks.

A vulnerability, CVE-2026-105218, has been identified in the Go payment library gopay prior to version 1.5.119. This flaw disables TLS certificate verification, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can exploit this vulnerability to access merchant credentials, signatures, and transaction data, potentially altering payment and refund responses. The risk is particularly high for services using this library on untrusted networks. No active exploitation or proof-of-concept code has been confirmed yet, but the urgency for remediation is emphasized. Affected entities should upgrade to the fixed version and monitor their payment API logs for unusual activity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-04
CVE-2026-105218 published
The vulnerability was disclosed, affecting gopay versions before 1.5.119, with a CVSS score of 9.1.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-105218 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
All versions of gopay prior to 1.5.119 are affected by this vulnerability.
Is there a patch available?
Yes, upgrading to gopay version 1.5.119 or later addresses the vulnerability.
What should I do if I suspect exploitation?
Review payment API logs for anomalies and consider rotating exposed credentials.