Apparently there was CVE-2018-20200 for an issue described as
CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the boolean values while hooking the application.
A report is at https://cxsecurity.com/issue/WLB-2018120252 was this forwarded already?