CVE-2026-105218 - gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client
CVE ID :CVE-2026-105218 Published : Oct. 4, 2026, 6:16 p.m. | 1 hour, 11 minutes ago Description :gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can...