Security/ xray-core · censorship-circumvention · certificate-verification · security

Xray-core hid a certificate verification bypass flaw

A certificate verification bypass in Xray-core was reportedly concealed rather than disclosed, according to a report on a network freedom forum.

A security report says Xray-core shipped a bug that let connections skip proper TLS certificate checks - and that the problem was kept quiet instead of fixed in the open.

The claim surfaced in a GitHub issue filed on net4people/bbs, a forum that tracks tools people use to get around internet censorship. According to the report, Xray-core - a widely used fork of the V2Ray proxy framework - contained a flaw that allowed certificate verification to be bypassed, undermining the TLS encryption that is supposed to protect users from interception. The issue frames this as concealment rather than a disclosed-and-patched bug. The discussion reached Hacker News, where it picked up 67 points and nine comments, modest but notable traction for a niche networking report.

Xray-core underpins proxy setups that activists, journalists, and ordinary users in restrictive countries depend on to reach the open internet. A certificate bypass is not a cosmetic bug - it is the exact failure mode that lets a network operator, or anyone positioned to intercept traffic, impersonate a server and read what is supposed to be encrypted. If the flaw was concealed rather than disclosed, that adds a trust problem on top of a technical one, for software whose entire value proposition is holding up under adversarial conditions.

Circumvention tools live and die on that trust; a hidden crypto bug is exactly the kind of thing that sends users looking for the next fork.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →