Official GitHub Security Advisory for Xray-core certificate verification bypass via pinnedPeerCertSha256.
Vulnerability: When pinning a well-known non-self-signed CA, an attacker can issue a leaf certificate through that Root CA (using attacker’s domain or IP) and hijack connections. In Go crypto/tls, when pinnedPeerCertSha256 is set, InsecureSkipVerify becomes true; if ServerName is empty (common for IP-address gRPC/Hysteria paths), hostname verification is skipped.
Affected scenarios: gRPC and Hysteria2 transports where GetTLSConfig() is called without tls.WithDestination(dest) — ServerName empty for IP addresses.
Expected: connection should fail. Actual: connection succeeds, enabling MITM.
Affected versions: >= v26.1.13 through versions before the July 2026 advisory fix (1.260327.1-0.20260710210335-64fada32b5b9).
Severity: High. CWE: Improper Validation of Certificate with Host Mismatch.
Initial silent fix landed in v26.2.6 (February 6, 2026) with commit message “Simplify cert’s verification code” — no security disclosure at release time. Researcher reported incomplete fix via GitHub Security Advisory July 3, 2026.