This reports a certificate verification bypass in Xray-core’s certificate pinning option pinnedPeerCertSha256 that allowed man-in-the-middle attacks. The older option pinnedPeerCertificateChainSha256 let users combine allowInsecure with custom chain pinning to safely use self-signed certificates by performing both regular verification and an additional pin check. Xray-core removed that option on Jan 9, 2026 and introduced pinnedPeerCertSha256. On Jan 16 the code was changed so regular verification was always skipped and only the custom pin logic ran. The reporter found a trivial bypass where an attacker can insert a forged leaf certificate anywhere in the chain and have the custom pinning logic validate that leaf, letting forged chains pass and enabling MITM attacks.
The reporter privately disclosed the bug to maintainers on Feb 6, 2026; maintainers committed a silent fix the same day with a commit message framed as “simplify the code” and released a new version without security disclosure. The reporter later found the fix incomplete on July 3, 2026 and escalated via a GitHub Security Advisory to prevent further concealment. The claim is that because users were forced to migrate off the older option and were not informed of the vulnerability, many were unknowingly left exposed for nearly half a year, and maintainers intentionally withheld notification.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.