Download Latest Version x-ui-windows-amd64.zip (87.3 MB)
Email in envelope

Get an email when there's a new version of 3X-UI

Home / v3.6.0
Name Modified Size InfoDownloads / Week
Parent folder
x-ui-windows-amd64.zip 2026-07-30 87.3 MB
x-ui-linux-armv6.tar.gz 2026-07-30 77.1 MB
x-ui-linux-armv5.tar.gz 2026-07-30 72.1 MB
x-ui-linux-armv7.tar.gz 2026-07-30 77.1 MB
x-ui-linux-amd64.tar.gz 2026-07-30 79.5 MB
x-ui-linux-s390x.tar.gz 2026-07-30 73.7 MB
x-ui-linux-386.tar.gz 2026-07-30 77.3 MB
x-ui-linux-arm64.tar.gz 2026-07-30 75.3 MB
README.md 2026-07-30 16.4 kB
v3.6.0 source code.tar.gz 2026-07-30 12.4 MB
v3.6.0 source code.zip 2026-07-30 13.2 MB
Totals: 11 Items   645.1 MB 27

🚀 Trend-First Overview, xray-core v26.7.28, Subscription Correctness & Panel Hardening

  • 🧭 Overview rebuilt as a command deck — the ten small cards are gone: four vitals tiles with 72-sample sparklines, a two-series throughput chart, a TCP/UDP connections chart, a grouped system strip, and a sidebar that became an auto-collapsed icon rail expanding on hover.
  • 🛡 xray-core v26.7.28 — the XMC finalmask breaking change is absorbed end to end: incomplete masks are rejected at save time with the missing field named, and only the offending mask is dropped at config-generation time so one bad row can no longer take every inbound offline.
  • 🔗 Subscription output correctness — a long run of link and format fixes (forwarded-URL trust, coalesced external refreshes, Clash scalars a YAML parser would misread, VLESS flow gating, external link names, WireGuard Allowed IPs) plus opt-in identity tokens on every link, raw download actions, live online status with a new ?format=info endpoint, and User-Agent format auto-detection.
  • 🔐 Panel surface tightenedopenapi.json moved behind session auth (it was serving the whole admin API surface unauthenticated), node API tokens became write-only, production sourcemaps no longer ship inside the binary, and the default freedom rules block private-range egress.
  • 🧹 Two large verified audit sweeps — 54 fixes from a repo-wide self-correcting audit and 16 more from a bug-label issue sweep, spanning email, node sync, subscriptions, xray config and the database.
  • 🗃 Data integrity — SQLite backup snapshots are taken online, legacy string tgId values in inbound settings are repaired on upgrade, and client_traffics rows are no longer deleted for detached-but-alive clients or left stale when an email is reused.
  • 🎛 Settings UX — settings sitting at their shipped default are tagged as such, clearing a port field keeps the stored port instead of writing zero, date-pickers commit on selection rather than on confirm, and the REALITY client version range is validated at save time.
  • 🧰 Frontend platform — the component Storybook became a validated, fully covered workbench and is published on the docs site, every axe accessibility violation in the library is resolved, react-router 8 and Node 24 LTS landed, and 210 dead translation keys were deleted with a test that fails the build on new ones.

ℹ️ Heads-up: The bundled core moved to xray-core v26.7.28, where the XMC finalmask usernames list was replaced by a required profiles array (username + UUID + both Mojang texture fields, no "default to Dream" fallback) — a mask saved by an older panel is now rejected at save time, and stripped from the generated config with a warning rather than failing the whole core, so anyone using that obfuscation must refill their profiles. A database migration repairs legacy string tgId values in inbound settings that previously broke every client operation on the affected inbound. Two surfaces changed behavior for existing setups: GET /panel/api/openapi.json now requires an authenticated session (it was reachable without one), and node API tokens are write-only — the API no longer returns them, so tooling that read a token back must store it at creation time. The default freedom finalRules also gain a geoip:private block rule, applied in place to installs still carrying the stock rules.

🆕 New

⚡️ Update & improvement

🐞 Bug fixed

Reports

Total Download

New Contributors

Full Changelog: https://github.com/MHSanaei/3x-ui/compare/v3.5.0...v3.6.0

Source: README.md, updated 2026-07-30