Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33661

26
FAUCET Score

CVE-2026-33661 describes a critical vulnerability in the Pay open-source payment SDK, prior to version 3.7.20, where the `verify_wechat_sign()` function unconditionally skips signature verification if the host is reported as 'localhost'. Rated 8.6 HIGH (CVSS), this flaw allows an unauthenticated attacker to forge fake WeChat Pay success notifications by sending a crafted HTTP request with a `Host: localhost` header, causing applications to mark orders as paid without actual payment. Despite no confirmed active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), its low attack complexity and network vector present a significant risk, with recent community discussions indicating awareness. Organizations using affected versions should prioritize upgrading to version 3.7.20.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.7.20CPE matchmatch criteria
cpe:2.3:a:yansongda:pay:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.50%
Probability of exploitation in next 30 days
EPSS Percentile
40.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0050 is in the 18th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: yansongda/payFixed in: 3.7.20
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-q938-ghwv-8gvchigh

WeChat Pay callback signature verification bypassed when Host header is localhost

Mar 25, 2026

References

github.com / yansongda/pay/commit/26987ebf789f1e7f0a85febb640986ab4289fd7f
Patch
github.com / yansongda/pay/releases/tag/v3.7.20
Release Notes
github.com / yansongda/pay/security/advisories/GHSA-q938-ghwv-8gvc
ExploitVendor Advisory