Xray-core Concealed A Certificate Verification Bypass Vulnerability
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get privacy and security gear delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

A reporter says a flaw in Xray-core’s pinnedPeerCertSha256 certificate pinning option could let an attacker insert a leaf certificate into a chain and bypass checks. The reporter says maintainers fixed the issue in February without disclosing it, and that a further bypass remained as of July 3, 2026; the account is an allegation in the supplied report.

A vulnerability reporter says a flaw in Xray-core’s pinnedPeerCertSha256 option allowed an attacker to insert a leaf certificate into a certificate chain and pass custom pinning checks, potentially enabling a man-in-the-middle attack. In a GitHub report, the researcher alleges maintainers patched the first issue on February 6, 2026, without telling users it was a security fix, and says a further bypass remained when they reported the matter through a GitHub Security Advisory on July 3.

The reporter traces the issue to changes in how Xray-core handled certificate pinning. According to the account, the project added pinnedPeerCertificateChainSha256 on October 21, 2021. The option was described as adding custom certificate-chain pinning alongside regular certificate verification. The report says Xray-core removed it on January 9, 2026, replacing it with pinnedPeerCertSha256. Users of self-signed certificates were then required to combine the replacement option with allowInsecure, the reporter says.

The report says Xray-core released the first version containing the vulnerable option on January 13, 2026. Three days later, maintainers changed its behavior so that regular certificate verification was always skipped and only the custom pinning logic was performed. The reporter alleges an attacker could insert a leaf certificate at any point in the chain and have that certificate pass the custom check. If so, the pinning check would not provide the intended protection against a forged certificate.

The reporter says they privately notified maintainers on February 6. The same day, according to the report, maintainers changed the code and released a version; the cited commit message described the change as simplifying code, and the release did not mention a security vulnerability. The reporter says a later review on July 3 found that this fix was incomplete under some circumstances. They then submitted a GitHub Security Advisory, saying Xray-core had not publicly disclosed the original flaw by that date.

At a glance
reportWhen: The reporter says the first flaw was pr…
The developmentA vulnerability reporter says Xray-core’s certificate pinning option allowed certificate verification to be bypassed and that a later fix remained incomplete.

How the Pinning Flaw Could Matter

Certificate verification helps a client confirm that it is communicating with the intended server. Certificate pinning adds a check against a certificate or chain expected by the client. The reported weakness matters because the reporter says an attacker could manipulate the chain so that the custom pinning check accepted a leaf certificate, while regular verification had already been disabled by the option’s behavior.

If the described conditions apply to a user’s setup, a successful bypass could allow an attacker positioned between the client and server to impersonate the server or intercept traffic. The report does not establish how many users were affected, whether attacks occurred, or which configurations were exposed. The account does, however, raise a practical concern for users who upgraded to the replacement option or relied on it with self-signed certificates: they may not have known that the reporter believed verification could be bypassed.

Disclosure also affects how users judge their exposure. A release that does not identify a security correction may not prompt affected users to update or review their configuration. The reporter argues that a public notice would have helped users respond. That criticism is the reporter’s assessment; the supplied material does not include a response from Xray-core maintainers.

Amazon

certificate pinning security tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

From Chain Pinning to Certificate Pinning

The options at the center of the report are tied to how Xray-core handles certificates. The reporter says the older chain-pinning option was designed to work in addition to ordinary verification. They also describe a use case for self-signed certificates: enable allowInsecure to bypass standard verification while using the pinning option as a separate check. Xray-core maintainers, in the reporter’s account, criticized allowInsecure as leaving users exposed to man-in-the-middle attacks.

The chronology described by the reporter is central to the allegation. Xray-core removed the older option on January 9, 2026; the first release with the replacement followed on January 13; and its verification behavior changed on January 16. The reporter says they found and privately reported the first bypass on February 6, the date they say it was patched and included in a release. They say a second, incomplete-fix issue led to the July 3 advisory. These dates and events come from the report supplied here and have not been independently corroborated in this article.

“A man-in-the-middle attacker could insert a leaf certificate at any place in the certificate chain, and the custom certificate pinning logic would verify the leaf certificate successfully.”

— The vulnerability reporter, in the GitHub report

Amazon

SSL/TLS certificate verification software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Scope and Remaining Fix Questions

The supplied report does not identify affected release numbers, provide a technical advisory with reproduction details, or quantify how many installations used the vulnerable option. It also does not establish that anyone exploited the flaw. The vulnerability mechanism, the claim that the February correction was incomplete, and the assertion that users remained exposed are presented by the reporter; the material provided does not include a maintainer response or independent technical assessment.

The report says the July 3 finding applied under certain circumstances, but does not specify those circumstances in the supplied text. It is not clear from this material whether a complete fix has since been released, whether users need to change configuration as well as upgrade, or what advice maintainers have given about self-signed certificates and allowInsecure.

Amazon

network security certificate management

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Advisory and User Guidance

The next useful updates would be a public advisory from Xray-core identifying affected versions, describing the corrected behavior, and explaining which versions users should install. Users need clear guidance on whether the current pinning option can be used safely with their configurations and whether any additional steps are necessary after upgrading.

The reporter’s GitHub Security Advisory submission may provide a route for publishing technical details, but the supplied material does not state its status or whether maintainers have responded. Until those details are available, users and administrators should consult Xray-core’s release notes and advisory channels for current version-specific instructions rather than infer their exposure from the report alone.

Amazon

man-in-the-middle attack prevention tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What vulnerability does the report describe?

The reporter says pinnedPeerCertSha256 could accept an inserted leaf certificate in a chain, bypassing the intended certificate pinning check and potentially enabling a man-in-the-middle attack.

When was the issue reported and fixed?

The reporter says they privately reported the first flaw on February 6, 2026, and that Xray-core changed the code and released a version that day. They allege that correction was incomplete, and say they filed a GitHub Security Advisory on July 3.

Were Xray-core users attacked?

The supplied report does not say that any attack occurred. It describes a potential attack and does not quantify affected users or confirmed exploitation.

Is there a confirmed complete fix?

The reporter alleges that a bypass remained under some circumstances after the February change. The supplied material does not provide a later fix status or current version guidance from Xray-core.

Source: hn

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

How Coordinated Disclosure Protects Users and Vendors

Discover how responsible, coordinated disclosure keeps your data safe and helps vendors patch vulnerabilities quickly. Learn the benefits and best practices.

Why Proof of Concept Does Not Mean Permission to Attack

A working exploit is evidence, not authorization. Learn the line between PoC research and illegal testing — plus safe ways to validate vulnerabilities.

CVE, CVSS, CWE and EPSS Explained Without Jargon

Learn what CVE, CVSS, CWE, and EPSS mean — without jargon. Understand how these tools help you spot, rate, and prioritize cybersecurity risks easily.

How Security Teams Prioritize Patches When Everything Looks Urgent

A practical guide to patch prioritization: severity scores vs. real risk, asset criticality, threat intel, and a step-by-step triage process you can use today.