Official GitHub Security Advisory for Xray-core certificate verification bypass via pinnedPeerCertSha256.

Vulnerability: When pinning a well-known non-self-signed CA, an attacker can issue a leaf certificate through that Root CA (using attacker’s domain or IP) and hijack connections. In Go crypto/tls, when pinnedPeerCertSha256 is set, InsecureSkipVerify becomes true; if ServerName is empty (common for IP-address gRPC/Hysteria paths), hostname verification is skipped.

Affected scenarios: gRPC and Hysteria2 transports where GetTLSConfig() is called without tls.WithDestination(dest) — ServerName empty for IP addresses.

Expected: connection should fail. Actual: connection succeeds, enabling MITM.

Affected versions: >= v26.1.13 through versions before the July 2026 advisory fix (1.260327.1-0.20260710210335-64fada32b5b9).

Severity: High. CWE: Improper Validation of Certificate with Host Mismatch.

Initial silent fix landed in v26.2.6 (February 6, 2026) with commit message “Simplify cert’s verification code” — no security disclosure at release time. Researcher reported incomplete fix via GitHub Security Advisory July 3, 2026.