Xray-core代理软件在pinnedPeerCertSha256选项中存在证书验证绕过漏洞,允许中间人攻击者在证书链中插入叶证书成功欺骗验证1。该漏洞源于2026年1月9日Xray-core移除pinnedPeerCertificateChainSha256并引入pinnedPeerCertSha256选项后产生1,在2026年1月13日首个包含该漏洞的版本发布1。
漏洞于2026年2月6日被发现者私下报告1,Xray-core随即以"简化代码"为由进行了隐蔽修复并发布新版本,但未向用户披露任何安全信息1。直至2026年7月3日,发现该修复不完整,漏洞在某些情况下仍可被绕过1,此时通过GitHub Security Advisory公开报告,用户已在未知情的情况下暴露于安全风险长达半年1。
Xray-core proxy software contained a certificate verification bypass vulnerability in its pinnedPeerCertSha256 option that allowed man-in-the-middle attackers to deceive verification by inserting leaf certificates into the certificate chain 1. The flaw was privately reported on February 6, 2026, after which Xray-core implemented a covert fix under the guise of "code simplification" without disclosing the security issue to users 1. This left users exposed to the vulnerability for approximately six months without their knowledge 1.
The vulnerability emerged following changes made to Xray-core's certificate pinning mechanism on January 9, 2026, when the pinnedPeerCertificateChainSha256 option was removed and replaced with pinnedPeerCertSha256 1. The first version containing the certificate verification bypass was released on January 13, 2026 1. On January 16, 2026, the pinnedPeerCertSha256 logic was modified to consistently skip regular certificate verification 1. On July 3, 2026, it was discovered that the fix was incomplete and the vulnerability could still be exploited under certain circumstances, prompting public disclosure through a GitHub Security Advisory 1.
评论
还没有评论,欢迎留下第一条。