hn.today

Xray-core concealed a certificate verification bypass vulnerability

github.com44 points0 comments
Screenshot of Xray-core concealed a certificate verification bypass vulnerability

This reports a certificate verification bypass in Xray-core’s certificate pinning option pinnedPeerCertSha256 that allowed man-in-the-middle attacks. The older option pinnedPeerCertificateChainSha256 let users combine allowInsecure with custom chain pinning to safely use self-signed certificates by performing both regular verification and an additional pin check. Xray-core removed that option on Jan 9, 2026 and introduced pinnedPeerCertSha256. On Jan 16 the code was changed so regular verification was always skipped and only the custom pin logic ran. The reporter found a trivial bypass where an attacker can insert a forged leaf certificate anywhere in the chain and have the custom pinning logic validate that leaf, letting forged chains pass and enabling MITM attacks.

The reporter privately disclosed the bug to maintainers on Feb 6, 2026; maintainers committed a silent fix the same day with a commit message framed as “simplify the code” and released a new version without security disclosure. The reporter later found the fix incomplete on July 3, 2026 and escalated via a GitHub Security Advisory to prevent further concealment. The claim is that because users were forced to migrate off the older option and were not informed of the vulnerability, many were unknowingly left exposed for nearly half a year, and maintainers intentionally withheld notification.

Read on github.com0 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.