highVulnerability

GHSA-5wf9-h793-w73c

### Summary Pinning a CA certificate via `pinnedPeerCertSha256` can lead to the success of MITM attacks in some cases. ### Details https://github.com/XTLS/Xray-core/blob/45cf2898ab12e97a55dd8f1f3d78d903340bdc9e/transport/internet/tls/config.go#L333-L347 If `r.Config.ServerName` is empty, `DNSName` will be empty and `certs[0].Verify(opts)` will not verify against dNSName or iPAddress. If a user pins a well-known and non-self-signed CA, an attacker can issue a leaf certificate through the Root CA (using the attacker's own domain name or IP address) and hijack the connections. In Go crypto/tls, either ServerName or InsecureSkipVerify must be specified in the `tls.Config`. If the user specifies `pinnedPeerCertSha256`, InsecureSkipVerify will always be true so ServerName can be empty. In most cases, if the user does not specify the `serverName`, Xray-core will use the server address as the `r.Config.ServerName`. Thanks to `GetTLSConfig(tls.WithDestination(dest))`, ServerName will usually not be empty. However, there are some leftovers: - https://github.com/XTLS/Xray-core/blob/45cf2898ab12e97a55dd8f1f3d78d903340bdc9e/transport/internet/hysteria/dialer.go#L348 `GetTLSConfig()` without `tls.WithDestination(dest)`. - https://github.com/XTLS/Xray-core/blob/45cf2898ab12e97a55dd8f1f3d78d903340bdc9e/transport/internet/grpc/dial.go#L139-L142 `GetTLSConfig()` without `tls.WithDestination(dest)`. Although ServerName will not be empty if `address` is a domain name, ServerName will be left empty if `address` is an IP address. ServerName is not equivalent to SNI. > ServerName is used to verify the hostname on the returned certificates unless InsecureSkipVerify is given. It is also included in the client's handshake to support virtual hosting unless it is an IP address. In these cases, if the user does not specify the `serverName`, Xray will not use the server address as the `r.Config.ServerName` and `r.Config.ServerName` will be left empty. ### PoC <details

Properties

ghsa_id
GHSA-5wf9-h793-w73c
summary
Xray-core: Pinning a CA certificate via pinnedPeerCertSha256 can lead to the success of MITM attacks
severity
high
last_source
GitHub Advisory Database
cve_id
GHSA-5wf9-h793-w73c
signal_observed_at
2026-10-03T01:59:23+00:00
is_ghsa_only
true
retrieved_at
2026-10-03T18:15:00+00:00
ghsa_published
2026-10-02T22:35:51Z
source_url
https://github.com/advisories/GHSA-5wf9-h793-w73c
ghsa_updated
2026-10-02T22:35:52Z

Related Entities (4)

VULNERABLE_TO (1)

←[Software]go/github.com/xtls/xray-core

REPORTED_BY (1)

→[Source]GitHub Advisory Database

AFFECTS (1)

→[Software]go/github.com/xtls/xray-core

HAS_WEAKNESS (1)

→[Weakness]Improper Validation of Certificate with Host Mismatch

Explore deeper with Ninja Signal's threat intelligence graph