Two critical vulnerabilities found in Radicle network protocol
The Radicle peer-to-peer code-collaboration project disclosed two critical flaws in its node network protocol: traffic between nodes lacks expected confidentiality, and broken peer authentication allows Node ID spoofing and reading private repositories. No patch is available yet; workarounds are published and a backward-incompatible update is underway.
- Radicle protocol does not provide expected confidentiality between nodes
- Peer authentication is broken, allowing Node ID impersonation
- Combined flaws let attackers read private repositories
- No fix released yet; a backward-incompatible update is coming
Read next
Security