Overview
Security considerations for proxy/VPN/circumvention tooling — where TLS misconfiguration can expose users to man-in-the-middle attacks despite tools marketed for privacy.
Timeline
- 2026-01-09: xray-core replaces
pinnedPeerCertificateChainSha256withpinnedPeerCertSha256 - 2026-01-16: Xray always skips standard TLS verification when pinning enabled
- 2026-02-06: Silent cert bypass fix in v26.2.6 (2026-10-04-xray-core-v26-2-6-release)
- 2026-07: Public GHSA-5wf9-H793-W73C advisory for incomplete fix
- 2026-10-04: net4people/bbs public disclosure of ~6-month exposure window (2026-10-04-xray-core-cert-verification-bypass)
Key Players
Analysis
High install base in regions with internet restrictions including Turkey. Users often lack security expertise to evaluate pinning configs. Supply-chain trust in open-source proxy tools requires responsible disclosure culture — silent fixes are especially harmful when users believe they are protected.