Back Original

Xray-core concealed a certificate verification bypass vulnerability

Disclaimer: I am the reporter of the vulnerability.

Xray-core maintainers look down on "skip certificate verification" feature (i.e. the allowInsecure option in Xray-core) or similar options in proxy software, arguing that this is equivalent to having no security measures at all and leaves users "streaking", exposing them to the risk of man-in-the-middle attacks. However, if a vulnerability in Xray-core itself causes users to be "streaking" and fall victim to man-in-the-middle attacks, Xray-core will cover it up and act as if nothing has happened.

On October 21, 2021, the pinnedPeerCertificateChainSha256 option, with no known issues, was added to Xray-core. This provides a double layer of security: if this option is enabled, custom certificate chain pinning logic will be performed in addition to the regular certificate verification. This also facilitates the use of self-signed certificates: to use a self-signed certificate securely, a user can enable both allowInsecure and pinnedPeerCertificateChainSha256 to skip the regular certificate verification and perform only the custom certificate chain pinning logic.

However, Xray-core later claimed that allowInsecure is insecure and enabling allowInsecure is like "streaking" and would leave users vulnerable to man-in-the-middle attacks.

On January 9, 2026, Xray-core removed pinnedPeerCertificateChainSha256 and replaced it with a new option, pinnedPeerCertSha256, to stop users from skipping certificate verification (or so-called "streaking"). For self-signed certificates, both allowInsecure and pinnedPeerCertSha256 must be enabled, which skips the regular certificate verification and only performs the custom certificate pinning logic. This should have helped the users to use self-signed certificates securely. However, pinnedPeerCertSha256 contains a certificate verification bypass vulnerability.

On January 13, 2026, Xray-core released the first version containing this certificate verification bypass vulnerability. Since the old option had been removed, users had no choice but to migrate to the new vulnerable option. At this point, the certificate verification defense was already teetering on the brink of collapse. Fortunately, as long as users neither use a self-signed certificate nor enable allowInsecure, the regular certificate verification could still provide some protection.

On January 16, 2026, Xray-core modified the logic of pinnedPeerCertSha256, making it always skip the regular certificate verification and only performs the custom certificate pinning logic. This means a protection layer has been missing: the regular certificate verification is always skipped. If a verification bypass vulnerability exists in pinnedPeerCertSha256 (and unfortunately, it does), the custom certificate pinning logic will fail to function, effectively leaving no certificate verification in place, which allows a man-in-the-middle attack to be successfully performed. At this point, the certificate verification defense has completely collapsed.

On February 6, 2026, I found the above certificate verification bypass vulnerability in Xray-core’s pinnedPeerCertSha256 and privately reported to Xray-core maintainers. A man-in-the-middle attacker could insert a leaf certificate at any place in the certificate chain, and the custom certificate pinning logic would verify the leaf certificate successfully, thereby leading to the success of man-in-the-middle attacks. This is an overly simple vulnerability; even without advanced security knowledge, I was able to discover it at a glance.

On the same day, Xray-core silently fixed this certificate verification bypass vulnerability, but the commit message beat around the bush, claiming it was to "simplify the code".

On the same day, Xray-core released a new version without mentioning the security vulnerability at all. Users were kept in the dark.

What's worse, on that same day, Xray-core posted the following statement on their Telegram channel: "Software must be designed with security at its core, eliminating the influence of the human factor to ensure that even the endest users aren’t streaking (left completely unprotected)." But this is the reality: due to Xray-core’s poor security design and the human factors it created, users were forced to migrate from a secure old option to an insecure new one, and the "endest users" have been unwittingly left exposed for nearly a month. Xray-core itself is exactly the human factor that has left users insecure and "streaking".

Xray-core could have taken corrective action by disclosing the security vulnerability to the users, thereby motivating them to upgrade to a new version that patches the vulnerability and minimizing the impact as much as possible. Unfortunately, they chose to cover it up.

As of July 3, 2026, Xray-core still had not disclosed the vulnerability to the users.

On July 3, 2026, I found that Xray-core’s fix for the vulnerability was incomplete; under certain circumstances, certificate verification could still be bypassed. To prevent the vulnerability from being maliciously concealed again, I had no choice but to report it via a GitHub Security Advisory. By that point, due to Xray-core's human factor, users had been unwittingly "streaking" for nearly half a year.

This is written in the hope that more people will realize how poor Xray-core's security record is.