Radicle: Disclosure of Vulnerability in the Network Protocol
Summary
Radicle discloses two critical vulnerabilities in its network protocol: plaintext, unauthenticated transport and a handshake impersonation flaw. All Radicle versions are affected, risking information leakage for private repositories and potential unauthorized access. The team advises stopping use of private repositories until a breaking major version upgrade fixes the issues, and outlines upcoming migration to a new networking stack (iroh).