Xray-core hid a certificate bypass that left users exposed for half a year
Xray-core concealed a certificate verification bypass vulnerability
In January 2026, Xray-core replaced its pinnedPeerCertificateChainSha256 option with pinnedPeerCertSha256, which always skips regular certificate verification. A bypass in the new option let a man-in-the-middle insert a leaf certificate anywhere in the chain. The maintainers fixed it silently, never told users, and only a later incomplete fix forced a GitHub advisory. Users were left unprotected for nearly six months.
Xray-core itself is exactly the human factor that has left users insecure and "streaking".