Pull to refresh
Logo
Xray-core certificate verification bypass went undisclosed for months

Xray-core certificate verification bypass went undisclosed for months

Rule Changes

A flaw in the pinnedPeerCertSha256 option let attackers impersonate TLS endpoints; the fix shipped silently in February

2 days ago: Researcher goes public

Overview

Updated 1 hour ago

Xray-core, a proxy tool that routes internet traffic, shipped a certificate verification bypass in January 2026. The flaw let an attacker impersonate a server and intercept encrypted connections when users pinned a well-known certificate authority.

A researcher reported the bug privately on February 6. The maintainers fixed it the same day, but the commit message said only 'simplify the code' and the release notes made no mention of a security issue. The researcher says the fix was incomplete and filed a formal advisory in July.

Why it matters

Users who relied on pinnedPeerCertSha256 could have had encrypted traffic intercepted for months without any warning to upgrade.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

6.8
CVSS severity score
Rated Medium by GitLab's advisory database
264
Days from vulnerable release to public disclosure
January 13 to October 4, 2026
v26.1.13–v26.7.11
Affected version range
All releases from the first vulnerable build to the patched one

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

October 2021 October 2026

8 events Latest: 2 days ago
Tap a bar to jump to that date
  1. Researcher goes public

    Latest Statement

    Researcher posts a detailed account on the net4people/bbs tracker accusing Xray-core of concealment.

  2. Advisory published

    Security

    GitHub publishes advisory GHSA-5wf9-h793-w73c for the Xray-core flaw.

  3. Researcher files formal advisory

    Security

    Researcher finds the fix incomplete and files a GitHub Security Advisory.

  4. Silent fix shipped

    Security

    Researcher privately reports the bypass; maintainers fix it silently the same day.

  5. Pinning logic weakened further

    Release

    Xray-core changes pinning logic to always skip standard certificate verification.

  6. First vulnerable release ships

    Release

    First release containing the vulnerable pinnedPeerCertSha256 option ships.

  7. Old pinning option removed

    Release

    Xray-core removes the old pinning option, replacing it with pinnedPeerCertSha256.

  8. Xray-core adds certificate pinning option

    Release

    Xray-core adds pinnedPeerCertificateChainSha256, a certificate pinning option.

Scenarios

1

Xray-core maintainers issue formal disclosure of the February fix

Possible Resolves by Jan 31, 2027

Discussed by: The researcher and security observers following the net4people/bbs thread

The maintainers publish a changelog entry or statement acknowledging the February 6, 2026 commit was a security patch. This would confirm or deny the reporter's account of a silent fix.

2

Story fades without further disclosure

Likely Resolves by Q1 2027

Discussed by: Observers noting the maintainers' continued silence

No further acknowledgment from the project. The July advisory remains the only formal record, and the concealment dispute fades from public attention.

3

New Xray-core security advisories surface

Possible Resolves by Q2 2027

Discussed by: Security researchers prompted by the controversy

The dispute draws attention to Xray-core's security practices, leading to audits that find additional flaws. New advisories are published for the project.

Historical Context

2 moments from history that rhyme with this story — and how they unfolded.

February 2014

Apple 'goto fail' (2014)

A duplicated line of code in Apple's TLS implementation disabled certificate verification in iOS and macOS. The bug let attackers intercept supposedly secure connections, including email and banking traffic. Apple shipped a fix within days.

Then

Apple released iOS 7.0.6 and OS X 10.9.2 to patch the flaw within days of discovery.

Now

The bug became a case study in how a single line of code can break TLS verification, and in the importance of code review for security-critical paths.

Why this matters now

Like the Xray-core flaw, 'goto fail' was a certificate verification bypass that enabled man-in-the-middle attacks. The difference is that Apple disclosed it publicly, while Xray-core's fix shipped silently.

May 2019

WhatsApp Pegasus spyware (2019)

Researchers found that a vulnerability in WhatsApp's video call feature let attackers install spyware on phones. The flaw was exploited to target human rights lawyers and journalists. WhatsApp fixed it and disclosed it publicly within days.

Then

WhatsApp urged users to update and published a security advisory. The spyware maker NSO Group denied involvement.

Now

The case highlighted how surveillance tools exploit messaging apps and the importance of prompt disclosure.

Why this matters now

WhatsApp disclosed the flaw publicly when it shipped the fix. Xray-core's maintainers did not, which is the core of the concealment accusation.

Sources

(6)