Xray-core hid a certificate bypass that left users exposed for half a year

Xray-core concealed a certificate verification bypass vulnerability

In January 2026, Xray-core replaced its pinnedPeerCertificateChainSha256 option with pinnedPeerCertSha256, which always skips regular certificate verification. A bypass in the new option let a man-in-the-middle insert a leaf certificate anywhere in the chain. The maintainers fixed it silently, never told users, and only a later incomplete fix forced a GitHub advisory. Users were left unprotected for nearly six months.

Xray-core itself is exactly the human factor that has left users insecure and "streaking".

More from this day

2026-10-04