Definition

Attack where an adversary intercepts and potentially alters communication between two parties who believe they are communicating directly — often enabled by broken TLS certificate verification.

Key Points

  • 2026-10-04: xray-core pinnedPeerCertSha256 bypass enabled MITM for users pinning CA certificates with IP-based endpoints (2026-10-04-xray-core-github-advisory-ghsa)
  • Attacker issues leaf certificate through pinned Root CA for own domain/IP
  • Empty ServerName + InsecureSkipVerify in Go TLS eliminates hostname checks

Sources