Radicle: Disclosure of Vulnerability in the Network Protocol
Summary
Radicle disclosed two critical vulnerabilities in its network protocol, impacting all versions. The issues include plaintext, unauthenticated network traffic and a broken peer authentication handshake, enabling potential information leakage and impersonation of allow-listed Node IDs. The disclosure recommends stopping use of private repositories until a fix is released, notes that a backward-incompatible major release will be required, and outlines mitigations and an upcoming migration to a new networking stack.