Xray-core concealed a certificate verification bypass vulnerability
timbill
71 points
9 comments
October 04, 2026
Related Discussions
Found 5 related stories in 93.3ms across 8,480 title embeddings via pgvector HNSW
- Luarocks.org remote code execution exploit cupcakerob · 18 pts · September 27, 2026 · 49% similar
- Plugin4Shell – Zero Click RCE Vulnerability found in top four coding agents fishthethis · 11 pts · September 17, 2026 · 49% similar
- Pre-Authentication RCE in WordPress Core patrikg · 18 pts · July 17, 2026 · 47% similar
- Radicle: Disclosure of Vulnerability in the Network Protocol lostmsu · 137 pts · September 23, 2026 · 47% similar
- A Blackstone real estate company exposed SSN digits, DOBs, addresses and more bearsyankees · 114 pts · August 24, 2026 · 47% similar
Discussion Highlights (4 comments)
cryptolobster
The reaction to Xray-core is disappointing
eriwang915
Xray-core's pinnedPeerCertSha256 treated an inserted leaf as the pinned cert, and the fix commit never called it a vulnerability.
usernomdeguerre
I get the impression that much of Xray's usage is in mainland China, do many other ecosystems use it? If not, why not? Naively I would expect solutions out of Mainland China to be more sophisticated due to the internet restrictions within the country and the number of people who are digitally-connected. But perhaps they cover for usecases one doesn't see outside the gfw.
soltanov
Fixing the code is only half of incident response. Without an advisory, affected-version range, and downstream notification, users cannot know whether they remain exposed.