www.vulncheck.com CVE-2026-105218 in Go-Pay Library Exposes Payment APIs
Article Content
- •CVE-2026-105218 is a critical vulnerability with a CVSS score of 9.1.
- •The flaw allows man-in-the-middle attacks by disabling TLS certificate verification.
- •Immediate upgrade to version 1.5.119 or later is recommended to mitigate risks.
A vulnerability, CVE-2026-105218, has been identified in the Go payment library gopay prior to version 1.5.119. This flaw disables TLS certificate verification, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can exploit this vulnerability to access merchant credentials, signatures, and transaction data, potentially altering payment and refund responses. The risk is particularly high for services using this library on untrusted networks. No active exploitation or proof-of-concept code has been confirmed yet, but the urgency for remediation is emphasized. Affected entities should upgrade to the fixed version and monitor their payment API logs for unusual activity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-105218 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions are affected?
Is there a patch available?
What should I do if I suspect exploitation?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…