External risk intelligence

gopay TLS Certificate Verification Bypass Exposes Payment Data

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-105218

The vulnerability exists within a software development library (gopay) used to build applications that communicate with payment providers. While the resulting applications may be internet-facing, the library itself is a build-time dependency integrated into custom code, not a standalone service or public-facing appliance.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the gopay software affects how secure connections are handled, potentially allowing attackers to impersonate payment providers. This could expose sensitive merchant credentials and transaction data, and enable unauthorized modifications to payment and refund processes. The main concern at this time is confirming if our use of this technology is relevant and exposed.

  • Payment security risk if this library is used.
  • Protects sensitive customer and financial data.
  • Verify if this library is used and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could impersonate payment provider APIs by exploiting a flaw in how the gopay library handles secure connections, allowing them to intercept and manipulate sensitive payment information.

  • Network access required.
  • TLS certificate verification bypassed.
  • Sensitive data exposure and modification.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow attackers to impersonate payment provider APIs when TLS certificate verification is not properly enforced. This could expose sensitive merchant credentials, transaction data, and allow for the modification of payment and refund responses.

  • Merchant credentials and transaction data.
  • Man-in-the-middle attacks when verification is not enforced.
  • Unauthorized transactions and data leakage.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in a TLS certificate verification library impacts applications that process payments. Application owners or development teams integrating this library are responsible for ensuring secure payment processing. The first step is to identify all applications using this library, assess their business criticality, and confirm their exposure to the internet or sensitive internal networks. Subsequently, a remediation plan can be developed based on the identified risks.

  • Application owners should address the issue.
  • Verify all payment processing integrations.
  • Plan remediation based on exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the gopay library?

gopay is a Go-based software development library designed to help developers integrate various payment gateway APIs into their own custom applications. It simplifies the process of communicating with financial services, such as handling requests and responses for payments, refunds, and order queries.

What does CVE-2026-105218 mean by TLS bypass?

This vulnerability falls under the Improper Certificate Validation (CWE-295) weakness class. It means the library fails to verify the identity of servers it connects to. Because it doesn't check if the payment provider's security certificate is authentic, an attacker can position themselves between your application and the API to intercept, read, or change sensitive data.

How does an attacker trigger this vulnerability?

The vulnerability occurs when your application makes outgoing network requests using the flawed client. An attacker must be in a position to intercept the network traffic to impersonate a legitimate payment provider. Simply using the library internally does not trigger the bug; the threat manifests when the application attempts to establish a secure connection that the attacker can then spoof.

Is my application at risk?

Risk depends on how you use the library. According to Halo Surface Signal, this is a build-time dependency for custom applications rather than a standalone, internet-facing appliance. If your custom application uses gopay to send requests over the public internet to payment APIs, it may be vulnerable. If it only communicates over highly restricted internal networks, the likelihood of an attacker positioning themselves to intercept traffic is much lower.

What should I do if I use gopay?

Your first step is to perform an inventory of your codebase to identify which applications include gopay versions older than 1.5.119. Once identified, prioritize these applications based on their connectivity to the internet and the sensitivity of the payment data they handle. Coordinate with your development team to update the library to a patched version to restore mandatory TLS certificate verification.

References