TL;DR
Get privacy and security gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
A vulnerability reporter says Xray-core’s pinnedPeerCertSha256 certificate-pinning option could accept an attacker-inserted leaf certificate, allowing certificate verification to be bypassed. The reporter says maintainers issued fixes in February and July 2026 but did not publicly disclose the flaw; those claims, the scope of affected users and the current remediation status require confirmation from the project.
A vulnerability reporter says Xray-core’s pinnedPeerCertSha256 option could allow a man-in-the-middle attacker to bypass certificate checks by inserting a leaf certificate into a certificate chain. In a July 3, 2026 GitHub report, the reporter alleged that an earlier fix was incomplete and that maintainers had not publicly disclosed the issue; the post does not include a response from Xray-core maintainers.
The report describes a change to Xray-core, software used to route network traffic through proxy connections. According to the reporter, an older setting, pinnedPeerCertificateChainSha256, was added on October 21, 2021, to check a pinned certificate chain alongside regular certificate verification. The reporter says the project removed that setting on January 9, 2026, and replaced it with pinnedPeerCertSha256. Users of the older option therefore had to migrate, the report says.
The reporter says the replacement option first appeared in a release on January 13, 2026, and that its behavior changed on January 16. In the reporter’s account, the option could skip regular certificate verification and rely on custom pinning logic. The reported bypass involved an attacker inserting a leaf certificate at any position in the chain, which the custom logic would accept. The report says this could enable a man-in-the-middle attack, but does not provide independent validation or details about conditions required to exploit it.
The reporter says they privately notified maintainers on February 6 and that a code change and new release followed the same day. They characterize the change as a fix that was not publicly identified as security-related. On July 3, they said they had found circumstances in which verification could still be bypassed and submitted a GitHub Security Advisory. The report does not identify the affected release range, provide a CVE identifier, or state which versions contain a complete fix.
How the Flaw Could Affect Connections
Certificate checks help a client determine whether it is connecting to the intended server. If the reported bypass works as described, a hostile party positioned between an Xray-core user and a server could present a certificate that the pinning logic accepts, potentially allowing interception or alteration of traffic. The report does not establish how widely the affected setting was used or whether any attacks occurred.
The account also raises a practical issue for users who configured certificate pinning for self-signed certificates. The reporter says the project changed the available option and its verification behavior in January, then issued a release after the February report. If users were not told that a security defect had been fixed, they may not have known to update. That sequence is the reporter’s characterization; the project has not provided a statement in the cited material.
As an affiliate, we earn on qualifying purchases.
Changes to Xray-core Certificate Options
The report centers on the relationship between regular certificate verification and certificate pinning. It says the earlier option could add a pinning check while retaining ordinary verification. For self-signed certificates, the reporter says users could combine allowInsecure with chain pinning, thereby relying on the custom pinning check. The report attributes to maintainers the view that allowInsecure is unsafe because it disables normal verification and can expose users to interception.
According to the reporter’s timeline, the old chain-pinning setting was replaced in January 2026 by a setting that pins an individual certificate. The reporter says that, on January 16, maintainers changed the new option so it always skipped regular verification. They argue that this left the custom pinning check as the sole defense, making a weakness in that logic more consequential. These descriptions come from the vulnerability report; the cited material does not include a maintainer account of the design rationale or a full technical review.
“A man-in-the-middle attacker could insert a leaf certificate at any place in the certificate chain.”
— The vulnerability reporter, in the July 3, 2026 GitHub post
network security certificate verification
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Scope and Fix Status Remain Unclear
The supplied report is written by the person who says they found and reported the vulnerability. It is an allegation, not an independent security assessment, and the cited material contains no response from Xray-core maintainers. The report does not specify the exact releases affected, the circumstances needed to exploit the issue, how many users relied on the option, or whether there is evidence of exploitation in the wild.
It also remains unclear what the February code change corrected, what bypass remained under the circumstances described in July, and whether maintainers have since issued a complete fix or a public advisory. The report says the project had not disclosed the vulnerability as of July 3, 2026; that statement does not establish the project’s disclosure status after that date.
As an affiliate, we earn on qualifying purchases.
Users Need Version Guidance
The next useful development would be a maintainer advisory identifying affected versions, the corrected release, and any configuration changes users should make. Users who rely on pinnedPeerCertSha256 can check Xray-core’s official release notes and security channels for current guidance, while avoiding assumptions about their exposure until the affected version range and required conditions are established.
A technical review of the July advisory and the relevant code changes could clarify whether the reported bypass is reproducible and whether the later fix closes it. Until that information is available, the reporter’s account is the main source for the vulnerability timeline, and the project’s response and current remediation status remain unconfirmed in the cited material.
man-in-the-middle attack prevention tools
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What vulnerability does the report describe?
The reporter says pinnedPeerCertSha256 could accept an attacker-inserted leaf certificate within a certificate chain, bypassing the intended verification and potentially enabling a man-in-the-middle attack.
Which Xray-core versions are affected?
The cited report does not provide a complete affected-version range or identify a release containing a confirmed complete fix. Users should consult official release and security guidance for version-specific information.
Did Xray-core fix the issue?
The reporter says maintainers made a change and released a new version on February 6, 2026, then alleges that the fix was incomplete when they reported another bypass on July 3. The supplied material does not establish the current fix status.
Has exploitation been confirmed?
The report describes a potential man-in-the-middle attack but provides no evidence that the vulnerability was exploited against users.
Source: hn
Evergreen bestsellers Picks
bestsellers
As an affiliate, we earn on qualifying purchases.
