HeadlinesBriefing HeadlinesBriefing.com

Xray-core covered up certificate verification bypass for 6 months

Hacker News •
×

Xray-core maintainers criticized the "skip certificate verification" feature as insecure, but covered up a vulnerability in their own software for half a year. On October 21, 2021, the `pinned Peer Certificate Chain Sha256` option was added, allowing secure use of self-signed certificates with both `allowInsecure` and pinning enabled. However, on January 9, 2026, Xray-core replaced it with `pinned Peer Cert Sha256`, claiming to prevent "streaking" (skipping certificate verification). This new option contained a certificate verification bypass vulnerability.

On January 13, 2026, the first vulnerable version was released. By January 16, 2026, Xray-core modified the logic to always skip regular certificate verification, leaving only the custom pinning logic. Since the pinning logic had a bypass, the certificate verification defense completely collapsed.

On February 6, 2026, the reporter discovered the vulnerability: a man-in-the-middle attacker could insert a leaf certificate anywhere in the chain, and the pinning logic would verify it successfully. The reporter privately disclosed it to maintainers. That same day, Xray-core silently fixed the vulnerability with a misleading commit message claiming "simplify the code", released a new version without mentioning the security issue, and kept users in the dark.

Xray-core had previously argued that skipping certificate verification was like "streaking", but their own vulnerability left users exposed to man-in-the-middle attacks. The cover-up lasted half a year, with no public acknowledgment of the security flaw.

Source: Hacker News · Summarized by HeadlinesBriefing