Xray-core concealed a certificate verification bypass vulnerability

timbill 71 points 9 comments October 04, 2026
github.com · View on Hacker News

Discussion Highlights (4 comments)

cryptolobster

The reaction to Xray-core is disappointing

eriwang915

Xray-core's pinnedPeerCertSha256 treated an inserted leaf as the pinned cert, and the fix commit never called it a vulnerability.

usernomdeguerre

I get the impression that much of Xray's usage is in mainland China, do many other ecosystems use it? If not, why not? Naively I would expect solutions out of Mainland China to be more sophisticated due to the internet restrictions within the country and the number of people who are digitally-connected. But perhaps they cover for usecases one doesn't see outside the gfw.

soltanov

Fixing the code is only half of incident response. Without an advisory, affected-version range, and downstream notification, users cannot know whether they remain exposed.

Semantic search powered by Rivestack pgvector
8,480 stories · 79,262 chunks indexed