Xray-core, a widely used proxy software, contained a certificate verification bypass vulnerability within its `pinnedPeerCertSha256` option. This flaw allowed attackers to perform man-in-the-middle attacks, compromising the security of user connections.
The `pinnedPeerCertSha256` option, which replaced a previous secure option, was introduced on January 9, 2026. The first version of Xray-core containing this vulnerability was released on January 13, 2026. The issue remained unaddressed and concealed for six months.
The vulnerability particularly affected users who enabled both `allowInsecure` and `pinnedPeerCertSha256` to securely use self-signed certificates. With the removal of the older, secure `pinnedPeerCertificateChainSha256` option, users were forced to migrate to the vulnerable `pinnedPeerCertSha256` option, leaving them exposed to man-in-the-middle attacks.
Xray-core maintainers had previously criticized the `allowInsecure` option, equating it to having no security. However, the introduction and concealment of this vulnerability in their own software created a similar security risk for users, despite their stated commitment to secure certificate verification.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Xray-core, a popular proxy software, concealed a certificate verification bypass vulnerability in its `pinnedPeerCertSha256` option for six months. This vulnerability allowed man-in-the-middle attacks, particularly affecting users who relied on the feature for secure use of self-signed certificates.