Security context

What an agent needs to avoid regressing past fixes and find the next vuln in this repo.

XTLS/Xray-core
main @ 45cf289
67
Fixes
0
CVEs
HIGH
Peak severity
22.2%
Coverage
Highlights
Denial of Service: 41 prior fixes. Scrutinize any change in this area.
transport/internet/tls: most-fixed (6 issues). Treat as high-risk during review.
41 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns

The bug types that recur here, drawn from past fixes, not open vulnerabilities.

Auth Bypass: Flaws in peer certificate verification, leaf validation against server names, and incorrect custom hash pinning routines have repeatedly allowed TLS authentication bypasses. Developer vigilance must be focused on ensuring strict SNI validation, complete SAN validation, and proper use of verification callbacks.
Denial of Service: Protocol framing, XTLS padding calculations, and splice handling have suffered from several out-of-bounds extend panics and nil dereferences. Robust buffer bounds checking and explicit nil validations are required during VLESS packet decoding.
Denial of Service: Race conditions in shared session contexts—such as concurrent map writes to session attributes during multiplexing—have historically triggered application-wide crashes. Safe context cloning or explicit mutex locking must be enforced across all transport boundaries.