Xray-core concealed a certificate verification bypass vulnerability
Xray-core, part of the Xray proxy suite, had a flaw that let attackers bypass TLS certificate checks, opening the door to man‑in‑the‑middle attacks. Security researchers identified the issue and released a patch adding stricter validation. Users should update to the latest version and monitor logs for any suspicious activity to stay protected. This vulnerability was traced to improper handling of certificate chains during handshake.