Xray-core Concealed A Certificate Verification Bypass Vulnerability
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get privacy and security gear delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

A vulnerability reporter says Xray-core’s pinnedPeerCertSha256 certificate-pinning option could accept an attacker-inserted leaf certificate, allowing certificate verification to be bypassed. The reporter says maintainers issued fixes in February and July 2026 but did not publicly disclose the flaw; those claims, the scope of affected users and the current remediation status require confirmation from the project.

A vulnerability reporter says Xray-core’s pinnedPeerCertSha256 option could allow a man-in-the-middle attacker to bypass certificate checks by inserting a leaf certificate into a certificate chain. In a July 3, 2026 GitHub report, the reporter alleged that an earlier fix was incomplete and that maintainers had not publicly disclosed the issue; the post does not include a response from Xray-core maintainers.

The report describes a change to Xray-core, software used to route network traffic through proxy connections. According to the reporter, an older setting, pinnedPeerCertificateChainSha256, was added on October 21, 2021, to check a pinned certificate chain alongside regular certificate verification. The reporter says the project removed that setting on January 9, 2026, and replaced it with pinnedPeerCertSha256. Users of the older option therefore had to migrate, the report says.

The reporter says the replacement option first appeared in a release on January 13, 2026, and that its behavior changed on January 16. In the reporter’s account, the option could skip regular certificate verification and rely on custom pinning logic. The reported bypass involved an attacker inserting a leaf certificate at any position in the chain, which the custom logic would accept. The report says this could enable a man-in-the-middle attack, but does not provide independent validation or details about conditions required to exploit it.

The reporter says they privately notified maintainers on February 6 and that a code change and new release followed the same day. They characterize the change as a fix that was not publicly identified as security-related. On July 3, they said they had found circumstances in which verification could still be bypassed and submitted a GitHub Security Advisory. The report does not identify the affected release range, provide a CVE identifier, or state which versions contain a complete fix.

At a glance
reportWhen: The reporter says the flaw was privatel…
The developmentA GitHub report published July 3, 2026, alleges that Xray-core’s certificate-pinning option had a verification bypass and that an earlier fix was incomplete.

How the Flaw Could Affect Connections

Certificate checks help a client determine whether it is connecting to the intended server. If the reported bypass works as described, a hostile party positioned between an Xray-core user and a server could present a certificate that the pinning logic accepts, potentially allowing interception or alteration of traffic. The report does not establish how widely the affected setting was used or whether any attacks occurred.

The account also raises a practical issue for users who configured certificate pinning for self-signed certificates. The reporter says the project changed the available option and its verification behavior in January, then issued a release after the February report. If users were not told that a security defect had been fixed, they may not have known to update. That sequence is the reporter’s characterization; the project has not provided a statement in the cited material.

Amazon

certificate pinning tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Changes to Xray-core Certificate Options

The report centers on the relationship between regular certificate verification and certificate pinning. It says the earlier option could add a pinning check while retaining ordinary verification. For self-signed certificates, the reporter says users could combine allowInsecure with chain pinning, thereby relying on the custom pinning check. The report attributes to maintainers the view that allowInsecure is unsafe because it disables normal verification and can expose users to interception.

According to the reporter’s timeline, the old chain-pinning setting was replaced in January 2026 by a setting that pins an individual certificate. The reporter says that, on January 16, maintainers changed the new option so it always skipped regular verification. They argue that this left the custom pinning check as the sole defense, making a weakness in that logic more consequential. These descriptions come from the vulnerability report; the cited material does not include a maintainer account of the design rationale or a full technical review.

“A man-in-the-middle attacker could insert a leaf certificate at any place in the certificate chain.”

— The vulnerability reporter, in the July 3, 2026 GitHub post

Amazon

network security certificate verification

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Scope and Fix Status Remain Unclear

The supplied report is written by the person who says they found and reported the vulnerability. It is an allegation, not an independent security assessment, and the cited material contains no response from Xray-core maintainers. The report does not specify the exact releases affected, the circumstances needed to exploit the issue, how many users relied on the option, or whether there is evidence of exploitation in the wild.

It also remains unclear what the February code change corrected, what bypass remained under the circumstances described in July, and whether maintainers have since issued a complete fix or a public advisory. The report says the project had not disclosed the vulnerability as of July 3, 2026; that statement does not establish the project’s disclosure status after that date.

Amazon

SSL/TLS inspection devices

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Users Need Version Guidance

The next useful development would be a maintainer advisory identifying affected versions, the corrected release, and any configuration changes users should make. Users who rely on pinnedPeerCertSha256 can check Xray-core’s official release notes and security channels for current guidance, while avoiding assumptions about their exposure until the affected version range and required conditions are established.

A technical review of the July advisory and the relevant code changes could clarify whether the reported bypass is reproducible and whether the later fix closes it. Until that information is available, the reporter’s account is the main source for the vulnerability timeline, and the project’s response and current remediation status remain unconfirmed in the cited material.

Amazon

man-in-the-middle attack prevention tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What vulnerability does the report describe?

The reporter says pinnedPeerCertSha256 could accept an attacker-inserted leaf certificate within a certificate chain, bypassing the intended verification and potentially enabling a man-in-the-middle attack.

Which Xray-core versions are affected?

The cited report does not provide a complete affected-version range or identify a release containing a confirmed complete fix. Users should consult official release and security guidance for version-specific information.

Did Xray-core fix the issue?

The reporter says maintainers made a change and released a new version on February 6, 2026, then alleges that the fix was incomplete when they reported another bypass on July 3. The supplied material does not establish the current fix status.

Has exploitation been confirmed?

The report describes a potential man-in-the-middle attack but provides no evidence that the vulnerability was exploited against users.

Source: hn

EVERGREEN BESTSE

Evergreen bestsellers Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Unauthenticated RCE In Motorola’s MR2600 Router

Security researchers disclose a critical unauthenticated RCE vulnerability in Motorola’s MR2600 router, raising concerns over device security and user data.

Why Old Routers Turn Into Silent Security Nightmares

Unlock the hidden risks of old routers turning into silent security nightmares and discover how to protect your network effectively.

How to Keep My Iphone Safe From Hackers

Take control of your iPhone's security with essential tips to outsmart hackers and protect your device from cyber threats.

Kimi K3 Exploited The Latest Redis Server

Cybersecurity researcher Kimi K3 has successfully exploited a recent vulnerability in the latest Redis server, raising concerns over security updates.