cybersecurity A field note by Vikrant Sharma
Xray-core hid a certificate verification bypass for six months
A proxy tool used to bypass censorship shipped with TLS verification disabled by default, then buried the fix in unrelated commits.
Xray-core is a popular proxy tool for bypassing internet censorship. Someone just discovered it shipped with certificate verification turned off by default for six months. The maintainer knew. The fix was committed without announcement, split across multiple unrelated PRs.
This is not a accident-then-patch story. The timeline shows the maintainer added allowInsecure: true as the default in March 2024. Users reported confusion about certificate errors in May. The setting was quietly changed back to secure defaults in September, buried in commits labelled as feature additions. No CVE. No security advisory. No mention in release notes.
The implications are grim for anyone using Xray to avoid state surveillance. Disabling certificate checks means a man-in-the-middle can intercept your traffic without the client noticing. The exact threat model Xray exists to defend against. For six months, the default config made interception trivial.
What makes this worse is the opacity. Open source does not mean secure by default when maintainers can bury security regressions in feature branches. The issue tracker shows users noticed weird behaviour but assumed they misconfigured something. That assumption is how silent downgrades survive.
The lesson here is not just about Xray. Any tool in your security stack that updates automatically needs someone reading every commit. Changelogs lie. Defaults change. If you run infrastructure that depends on TLS verification, pin your versions and audit the diffs yourself. Trust is not a deployment strategy.
Source: Xray-core concealed a certificate verification bypass vulnerability