Retour à la veille

CVE-2026-105218

Publié : 4 octobre 2026
Modifié : 4 octobre 2026
Lien officiel NVD
Score CVSS
7.4
HIGH

Description détaillée

gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Références et Patchs