VRChat's bundled yt-dlp rejects valid Let's Encrypt certificates served by Cloudflare
tracked
Vesturo
We've identified a certificate-validation issue affecting VRChat's bundled yt-dlp when resolving HTTPS URLs served through Cloudflare Universal SSL using Let's Encrypt.
This does not appear to be an issue with an expired website certificate or an individual user's system configuration.
The affected Cloudflare certificate is currently valid:
Certificate Authority: Let's Encrypt
Certificate type: Cloudflare Universal SSL
Expiration: 2026-10-16
Validity period: 3 months
Despite this, VRChat's bundled resolver fails with:
[SSL: CERTIFICATE_VERIFY_FAILED]
certificate verify failed: certificate has expired (_ssl.c:1002)
Reproducibility
The issue reproduces consistently when using VRChat's currently bundled yt-dlp:
yt-dlp version: 2026.07.04
The same HTTPS endpoints:
* Validate normally in modern browsers
* Validate normally through Windows curl.exe / Schannel
* Are served using a currently valid Cloudflare Universal SSL certificate
* Resolve successfully through alternative/custom yt-dlp integrations
* Consistently fail certificate validation through VRChat's bundled yt-dlp
This makes the problem appear to be an incompatibility between VRChat's bundled yt-dlp certificate-validation environment and the Let's Encrypt certificate chain currently being served by Cloudflare.
Isolating the failure
Using VRChat's own yt-dlp.exe, resolving an affected URL normally results in:
CERTIFICATE_VERIFY_FAILED
certificate has expired
Running the exact same request with:
--no-check-certificates
immediately succeeds and returns the expected media URL.
We are not suggesting disabling certificate validation as a workaround. This was used solely as an A/B diagnostic and confirms that certificate verification itself is the point of failure.
Why this may have wider impact
The affected hostname is not serving a manually configured or unusual certificate. It is using a standard Cloudflare Universal SSL certificate issued by Let's Encrypt.
Because Cloudflare deploys Universal SSL certificates across a very large number of domains, this may potentially affect other VRChat video services or websites whose Cloudflare edge certificate is issued through the same or a similar Let's Encrypt chain.
This therefore may not be limited to one video provider or one unusual URL configuration.
Expected behavior
Currently valid HTTPS certificates trusted by standard browsers and operating-system TLS implementations should also validate successfully through VRChat's video resolver.
Actual behavior
VRChat's bundled yt-dlp reports the Cloudflare-served Let's Encrypt certificate chain as expired and refuses to resolve the URL, despite the certificate itself currently being valid.
Temporary workaround
Alternative/custom yt-dlp integrations do not appear to exhibit the same issue and can currently resolve the affected URLs.
This is not an appropriate long-term solution for world authors or normal users, but it may provide a temporary workaround for users already running such tools.
Reproduction URLs
We would prefer not to publish affected production endpoints publicly.
We have confirmed URLs that reproduce the issue consistently and can provide them, along with certificate details and our testing results, privately to VRChat staff.
VRChat staff are welcome to contact us and we'll provide the affected URLs and full reproduction information privately.
Log In
StormRel
updated the status to
tracked
WubTheCaptain
"AI" (large language model) slop report, no affected URL included to reproduce the issue.
Vesturo
WubTheCaptain URLs not included on purpose as this is a report for vrchat staff and not an invitation for random vrchatters to poke around my non-public backend shenanigans.
+ following basic report etiquette doesn't mean it's LLM written? �
WubTheCaptain
Vesturo Alright, you made go through various Cloudflare CDN backed upload/video services such as shr.ocen.uk (s.ocen.uk), cloudflare.tv, etc. None of them had Let's Encrypt issued certificates to reproduce the issue (usually Google Trust issued with expire dates similar to yours).
I've scoured through recent upstream yt-dlp issues about CERTIFICATE_VERIFY_FAILED and found none reported. I've also gone through recent Let's Encrypt blog posts to remind myself if there was changes to subcertificate issuance, and I am not sure.
Please drop a VRChat support ticket number in this topic with an affected URL privately, if you think this issue is not LLM hallucinated. You can create a support request privately at https://vrch.at/support.
Vesturo
WubTheCaptain As you said yourself, all the services you tested use GTS, so they don't apply to this Canny at all lol.
If VRChat staff requests more information from me, I'll happily provide it. In the meantime, the issue can be reproduced with the information already provided above :)
VRChat explicitly asks users to report bugs through Canny unless staff requests additional information, so I'll stick to their process rather than whatever some random VRChatter tells me to do. I hope you understand that :)
WubTheCaptain
I also tested litterbox.chatbox.moe video playback despite not being Cloudflare backed as reported in OP to be the issue, but serving a YE2 Let's Encrypt certificate. The issue was not with Let's Encrypt by itself.
Photo Viewer
View photos in a modal
Vesturo
i love how my markdown sometimes works and sometimes doesn't, what the hecc canny
Vesturo
edited to remove broken markdown