Definition
Attack where an adversary intercepts and potentially alters communication between two parties who believe they are communicating directly — often enabled by broken TLS certificate verification.
Key Points
- 2026-10-04: xray-core
pinnedPeerCertSha256bypass enabled MITM for users pinning CA certificates with IP-based endpoints (2026-10-04-xray-core-github-advisory-ghsa) - Attacker issues leaf certificate through pinned Root CA for own domain/IP
- Empty
ServerName+InsecureSkipVerifyin Go TLS eliminates hostname checks