Xray-core 隐藏了一个证书验证绕过漏洞
Xray-core concealed a certificate verification bypass vulnerability

原始链接: https://github.com/net4people/bbs/issues/672

该报告称,Xray-core 在 2026 年 1 月引入了 `pinnedPeerCertSha256`,用于绕过证书验证,并以此取代更安全的 `pinnedPeerCertificateChainSha256`。新选项最初仅允许在处理自签名证书时搭配 `allowInsecure` 使用,但后来开始无条件跳过正常的证书验证。由于其证书固定逻辑会接受证书链中任意位置由攻击者提供的叶证书,中间人攻击者因此能够同时绕过这两项安全保护。 该问题于 2026 年 2 月 6 日被私下报告,并在当天得到修复,但发布说明和公开声明均未披露其安全影响。报告者后来发现,在某些情况下,这一修复仍不完整,并于 7 月 3 日发布了一份 GitHub 安全公告。 该报告批评 Xray-core 迫使用户从安全机制迁移到存在漏洞的机制,并在未公开说明的情况下修复问题,使用户在数月内持续暴露于风险之中。报告认为,用户应及时获知漏洞信息,以便升级软件并降低风险。

Hacker News 最新 | 往期 | 评论 | 提问 | 展示 | 工作 | 提交 登录 Xray-core 隐瞒了一个证书验证绕过漏洞 (github.com/net4people) 49 分 由 timbill 提交 7 小时前 | 隐藏 | 往期 | 收藏 | 1 条评论 帮助 cryptolobster 10 分钟前 [–] 大家对 Xray-core 的反应令人失望。 回复 考虑申请 YC 2027 年冬季批次! 申请通道开放至 11 月 2 日。 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请加入 YC | 联系我们 搜索:
相关文章

原文

Disclaimer: I am the reporter of the vulnerability.

Xray-core maintainers look down on "skip certificate verification" feature (i.e. the allowInsecure option in Xray-core) or similar options in proxy software, arguing that this is equivalent to having no security measures at all and leaves users "streaking", exposing them to the risk of man-in-the-middle attacks. However, if a vulnerability in Xray-core itself causes users to be "streaking" and fall victim to man-in-the-middle attacks, Xray-core will cover it up and act as if nothing has happened.

On October 21, 2021, the pinnedPeerCertificateChainSha256 option, with no known issues, was added to Xray-core. This provides a double layer of security: if this option is enabled, custom certificate chain pinning logic will be performed in addition to the regular certificate verification. This also facilitates the use of self-signed certificates: to use a self-signed certificate securely, a user can enable both allowInsecure and pinnedPeerCertificateChainSha256 to skip the regular certificate verification and perform only the custom certificate chain pinning logic.

However, Xray-core later claimed that allowInsecure is insecure and enabling allowInsecure is like "streaking" and would leave users vulnerable to man-in-the-middle attacks.

On January 9, 2026, Xray-core removed pinnedPeerCertificateChainSha256 and replaced it with a new option, pinnedPeerCertSha256, to stop users from skipping certificate verification (or so-called "streaking"). For self-signed certificates, both allowInsecure and pinnedPeerCertSha256 must be enabled, which skips the regular certificate verification and only performs the custom certificate pinning logic. This should have helped the users to use self-signed certificates securely. However, pinnedPeerCertSha256 contains a certificate verification bypass vulnerability.

On January 13, 2026, Xray-core released the first version containing this certificate verification bypass vulnerability. Since the old option had been removed, users had no choice but to migrate to the new vulnerable option. At this point, the certificate verification defense was already teetering on the brink of collapse. Fortunately, as long as users neither use a self-signed certificate nor enable allowInsecure, the regular certificate verification could still provide some protection.

On January 16, 2026, Xray-core modified the logic of pinnedPeerCertSha256, making it always skip the regular certificate verification and only performs the custom certificate pinning logic. This means a protection layer has been missing: the regular certificate verification is always skipped. If a verification bypass vulnerability exists in pinnedPeerCertSha256 (and unfortunately, it does), the custom certificate pinning logic will fail to function, effectively leaving no certificate verification in place, which allows a man-in-the-middle attack to be successfully performed. At this point, the certificate verification defense has completely collapsed.

On February 6, 2026, I found the above certificate verification bypass vulnerability in Xray-core’s pinnedPeerCertSha256 and privately reported to Xray-core maintainers. A man-in-the-middle attacker could insert a leaf certificate at any place in the certificate chain, and the custom certificate pinning logic would verify the leaf certificate successfully, thereby leading to the success of man-in-the-middle attacks. This is an overly simple vulnerability; even without advanced security knowledge, I was able to discover it at a glance.

On the same day, Xray-core silently fixed this certificate verification bypass vulnerability, but the commit message beat around the bush, claiming it was to "simplify the code".

On the same day, Xray-core released a new version without mentioning the security vulnerability at all. Users were kept in the dark.

What's worse, on that same day, Xray-core posted the following statement on their Telegram channel: "Software must be designed with security at its core, eliminating the influence of the human factor to ensure that even the endest users aren’t streaking (left completely unprotected)." But this is the reality: due to Xray-core’s poor security design and the human factors it created, users were forced to migrate from a secure old option to an insecure new one, and the "endest users" have been unwittingly left exposed for nearly a month. Xray-core itself is exactly the human factor that has left users insecure and "streaking".

Xray-core could have taken corrective action by disclosing the security vulnerability to the users, thereby motivating them to upgrade to a new version that patches the vulnerability and minimizing the impact as much as possible. Unfortunately, they chose to cover it up.

As of July 3, 2026, Xray-core still had not disclosed the vulnerability to the users.

On July 3, 2026, I found that Xray-core’s fix for the vulnerability was incomplete; under certain circumstances, certificate verification could still be bypassed. To prevent the vulnerability from being maliciously concealed again, I had no choice but to report it via a GitHub Security Advisory. By that point, due to Xray-core's human factor, users had been unwittingly "streaking" for nearly half a year.

This is written in the hope that more people will realize how poor Xray-core's security record is.

联系我们 contact @ memedata.com