← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Xray-core concealed certificate verification bypass vulnerability for six months

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Xray-core's `pinnedPeerCertSha256` option contained a bypass vulnerability.
  • The vulnerability was present from January 13, 2026.
  • Xray-core removed the previous secure option, forcing migration to the vulnerable one.
  • The issue allowed man-in-the-middle attacks, especially with self-signed certificates.

Vulnerability in Xray-core's Certificate Verification

Xray-core, a widely used proxy software, contained a certificate verification bypass vulnerability within its `pinnedPeerCertSha256` option. This flaw allowed attackers to perform man-in-the-middle attacks, compromising the security of user connections.

Timeline of the Vulnerability

The `pinnedPeerCertSha256` option, which replaced a previous secure option, was introduced on January 9, 2026. The first version of Xray-core containing this vulnerability was released on January 13, 2026. The issue remained unaddressed and concealed for six months.

Impact on Users

The vulnerability particularly affected users who enabled both `allowInsecure` and `pinnedPeerCertSha256` to securely use self-signed certificates. With the removal of the older, secure `pinnedPeerCertificateChainSha256` option, users were forced to migrate to the vulnerable `pinnedPeerCertSha256` option, leaving them exposed to man-in-the-middle attacks.

Developer Stance and User Risk

Xray-core maintainers had previously criticized the `allowInsecure` option, equating it to having no security. However, the introduction and concealment of this vulnerability in their own software created a similar security risk for users, despite their stated commitment to secure certificate verification.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 04

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Xray-core, a popular proxy software, concealed a certificate verification bypass vulnerability in its `pinnedPeerCertSha256` option for six months. This vulnerability allowed man-in-the-middle attacks, particularly affecting users who relied on the feature for secure use of self-signed certificates.