Skip to content

[GHSA-8f6w-7m2h-mfwg] gopay before 1.5.119 disables TLS certificate... - #10179

Open
ranjiGT wants to merge 1 commit into
ranjiGT/advisory-improvement-10179from
ranjiGT-GHSA-8f6w-7m2h-mfwg
Open

ranjiGT wants to merge 1 commit into
ranjiGT/advisory-improvement-10179from
ranjiGT-GHSA-8f6w-7m2h-mfwg

Conversation

@ranjiGT

@ranjiGT ranjiGT commented Oct 5, 2026

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • Description
  • References
  • Source code location
  • Summary

Comments
Adds precise Go package and affected-version metadata based on upstream release history.

The insecure default TLS configuration in pkg/xhttp/client.go, using tls.Config{InsecureSkipVerify: true}, was introduced by commit 988e18a0f7e75ce002e96614e8d8a1a354f593f8 before the v1.5.27 release.

Verification against upstream tags shows that v1.5.26 does not contain this insecure default in pkg/xhttp/client.go, while v1.5.27 does. The configuration remains present through v1.5.118.

Commit f6df04fd4f64a2ad2c303ba063b6502bfdd259fd, released as v1.5.119, removes InsecureSkipVerify: true from the default client.

Therefore the affected range is >= 1.5.27, < 1.5.119, with 1.5.119 as the patched version.

The malformed CVSS v4 vector present in the existing advisory is also normalized to the equivalent base vector accepted by GitHub's CVSS v4 parser.

Copilot AI balanced review requested due to automatic review settings October 5, 2026 12:20
@github-actions
github-actions Bot changed the base branch from main to ranjiGT/advisory-improvement-10179 October 5, 2026 12:21

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The affected range misses the former Go module path, and valid CVSS v3 metadata is removed.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Refines the GoPay TLS verification advisory with package/version metadata and clearer remediation details.

Changes:

  • Adds affected Go module ranges and references.
  • Expands the vulnerability description and summary.
  • Normalizes the CVSS v4 vector.
File Description
GHSA-8f6w-7m2h-mfwg.json Updates GoPay advisory metadata, severity, affected versions, and references.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +18 to 36
{
"package": {
"ecosystem": "Go",
"name": "github.com/go-pay/gopay"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.5.27"
},
{
"fixed": "1.5.119"
}
]
}
]
}

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed against the upstream release tags.

v1.5.41 uses the Go module path:

github.com/iGoogle-ink/gopay

Starting with v1.5.42, the module path changes to:

github.com/go-pay/gopay

The upstream go.mod diff between v1.5.41 and v1.5.42 confirms the rename:

-module github.com/iGoogle-ink/gopay
+module github.com/go-pay/gopay

Comment on lines 12 to +15
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
}

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment 2 — Retain CVSS v3.1

Confirmed. The original advisory contains the following CVSS v3.1 vector:

`CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N`

This existing CVSS v3.1 entry should be retained alongside the normalized CVSS v4 vector:

`CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N`

The intent of the change is only to normalize the malformed CVSS v4 vector, not to remove the existing valid CVSS v3.1 severity metadata.

I attempted to apply the suggested change, but GitHub returned `Failed to commit suggested changes`.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants