Menu

Post image 1
Post image 2
1 / 2
0

Disclosure of Vulnerability in the Network Protocol

Hacker News·13 days ago
#2JZe2fHQ
Reading 0:00
15s threshold

Radicle is a peer-to-peer, local-first code collaboration stack built on Git. 23.09.2026 Summary What happened? Two critical security vulnerabilities in the network protocol used by Radicle nodes were reported. Which versions are affected? All versions of Radicle that were released to date are vulnerable. What is the issue? Network traffic between nodes is not encrypted and not authenticated. Authentication of repository contents via Signed References still detects if attackers along the network path between two nodes modify objects in transit. Thus, the main concern is information leakage, i.e., attackers along the network path between two nodes reading objects in transit. For public repositories, information leakage is less of a concern. However, encryption in transit is crucial for private repositories. What should users do? We recommend to stop using private repositories until a fix is released. When will the fixed version be released?…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More