Xray-core accused of concealing a certificate verification bypass

A post on the net4people/bbs tracker (issue #672) accuses the proxy software Xray-core of covering up a certificate verification bypass for about half a year. The author opens with a disclaimer: he is the reporter of the vulnerability. His name is not given. Everything below is his account; the text includes no response from the Xray-core maintainers.\n\nThe reporter lays out a timeline. On 21 October 2021 the pinnedPeerCertificateChainSha256 option was added to Xray-core, with no known issues. It added a second layer: custom certificate chain pinning on top of regular certificate verification. It also let people use self-signed certificates safely, by enabling both allowInsecure and the pinning option so that regular verification is skipped and only the pinning logic runs.\n\nXray-core later argued that allowInsecure is insecure and that enabling it is like 'streaking', leaving users open to man-in-the-middle attacks. On 9 January 2026 it removed the old option and replaced it with pinnedPeerCertSha256. For self-signed certificates, both allowInsecure and pinnedPeerCertSha256 must be enabled. The reporter says the new option contains a certificate verification bypass.\n\nOn 13 January 2026 Xray-core released the first version with the flaw. Because the old option was gone, he says, users had no choice but to migrate to the vulnerable one. At that point, as long as users used neither a self-signed certificate nor allowInsecure, regular verification still gave some protection. On 16 January 2026 Xray-core changed the logic of pinnedPeerCertSha256 so that it always skips regular verification and runs only the custom pinning. The reporter's argument: with that layer gone, any bypass in the pinning logic leaves no certificate verification at all, so a man-in-the-middle attack succeeds.\n\nOn 6 February 2026 he found the bypass and privately reported it to the maintainers. He describes how it works: an attacker in the middle could insert a leaf certificate at any place in the certificate chain, and the custom pinning logic would verify that leaf certificate successfully. He calls it an overly simple vulnerability that he spotted at a glance without advanced security knowledge.\n\nThe same day, he says, Xray-core silently fixed it. The commit message beat around the bush and said the change was to 'simplify the code'. A new version went out the same day with no mention of a security issue. Also that day, Xray-core posted on its Telegram channel: 'Software must be designed with security at its core, eliminating the influence of the human factor to ensure that even the endest users aren’t streaking (left completely unprotected).' The reporter reads this as ironic and says users had been unwittingly left exposed for nearly a month. He argues that disclosure would have pushed users to upgrade and limited the damage.\n\nAs of 3 July 2026, he writes, Xray-core still had not disclosed the vulnerability to users. On that date he found the fix was incomplete: under certain circumstances, certificate verification could still be bypassed. To stop it being concealed again, he says, he had no choice but to report it through a GitHub Security Advisory. By then, he says, users had been unwittingly 'streaking' for nearly half a year. He ends by saying he wrote the post so that more people realise how poor Xray-core's security record is.
Key facts
- The reporter of a certificate verification bypass in Xray-core's pinnedPeerCertSha256 option says the maintainers fixed it silently on 6 February 2026, the day he reported it privately.
- He says the commit message described the change as 'simplify the code' and the same-day release did not mention a security issue.
- Timeline he gives: old option removed 9 January 2026, first vulnerable release 13 January, logic changed to always skip regular verification 16 January.
- He says a man-in-the-middle attacker could insert a leaf certificate anywhere in the chain and the pinning logic would accept it.
- On 3 July 2026 he says he found the fix incomplete and filed a GitHub Security Advisory; he says users still had not been told.
Why it matters
Xray-core is proxy software, and the flaw sits in a feature meant to protect connections with self-signed certificates. The reporter's central claim is a disclosure failure on top of a design failure: a fix shipped without telling users, so they had no reason to upgrade. He also points to a contradiction. The project criticises allowInsecure as leaving users 'streaking', yet its own option, he says, ended up with the same effect.
Who it affects
Per the reporter, users of Xray-core who relied on pinnedPeerCertSha256, especially those with self-signed certificates and allowInsecure enabled, from the 13 January 2026 release until the 6 February fix. He says the old option was removed, so migration to the new one was forced. No user counts or number of affected deployments are given.
How to use it
The text offers no instructions or version numbers. The practical reading is for operators who use pinnedPeerCertSha256: check which release you run, since the reporter says a fix landed on 6 February 2026 and that a further gap was reported on 3 July 2026 through a GitHub Security Advisory. Whether that report has since been patched is not stated.
How solid is it
It is a first-person account by the self-described reporter, who is not named. Each claim in it is his own, and each date is his. The text has no CVE or CVSS score, no release version numbers, and no reply from the Xray-core maintainers. The technical mechanism is described in a sentence or two. Treat it as credible but unconfirmed by the other side.
Risks and caveats
The post is openly an advocacy piece: it says it was written so more people realise how poor Xray-core's security record is. Its exposure windows are loose, 'nearly a month' in one place and 'nearly half a year' in another, and they are his estimates. No evidence of exploitation in the wild is given. The account of motive, that the maintainers deliberately concealed the flaw, is the reporter's interpretation, and the maintainers' side is absent.
“Software must be designed with security at its core, eliminating the influence of the human factor to ensure that even the endest users aren’t streaking (left completely unprotected).”
— Xray-core Telegram channel statement, as quoted by the reporter