<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:gopay:gopay:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3agopaygopay/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 04 Oct 2026 18:54:16 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3agopaygopay/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>TLS Verification Bypass in gopay Library</title><link>https://feed.craftedsignal.io/briefs/2026-10-gopay-tls-mitm/</link><pubDate>Sun, 04 Oct 2026 18:54:16 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-gopay-tls-mitm/</guid><description>The gopay library versions prior to 1.5.119 contain a flaw in defaultClient() that disables TLS certificate verification, enabling man-in-the-middle attacks to intercept sensitive payment data.</description><content:encoded><![CDATA[<p>The gopay library versions before 1.5.119 exhibit a critical security flaw located in the defaultClient() function within the file pkg/xhttp/client.go. This function improperly disables TLS certificate verification, a security mechanism essential for ensuring encrypted communications remain private and authenticated. Consequently, this vulnerability allows a man-in-the-middle (MitM) attacker positioned on the network path between the application and the payment provider API to intercept, read, and modify traffic.</p>
<p>An attacker exploiting this vulnerability can present fraudulent certificates to the application, effectively impersonating the payment provider. This enables the theft of sensitive merchant credentials, digital signatures, and transactional data. Furthermore, the attacker can manipulate the content of payment, refund, or order query responses, potentially leading to unauthorized financial operations or data integrity compromises. Defenders should prioritize updating to version 1.5.119 or later to enforce proper TLS validation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows for unauthorized access to sensitive financial information, including merchant credentials and transaction data. An attacker can manipulate payment flows, potentially resulting in fraudulent transactions or incorrect refund processing. This flaw impacts any merchant application relying on the affected gopay library for payment integration, with the severity of potential damage proportional to the volume and criticality of transactions processed by the compromised system.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the gopay dependency in all projects to version 1.5.119 or later to ensure TLS certificate verification is re-enabled.</li>
<li>Audit application code for dependencies utilizing the affected defaultClient() function and ensure they are patched.</li>
<li>Monitor network traffic for anomalous outbound connections from application servers to unknown or self-signed payment provider endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>tls</category><category>mitm</category><category>library</category></item></channel></rss>