
Radicle: Disclosure of Vulnerability in the Network Protocol
Radicle has disclosed two critical security vulnerabilities in its network protocol that affect all currently released versions. The flaws allow attackers to read unencrypted data in transit and impersonate authenticated nodes to access private repositories. Users are advised to immediately stop using private repositories over the network until a breaking security update is released.
- ▪All versions of Radicle released to date are vulnerable to unencrypted network traffic and broken peer authentication.
- ▪The vulnerabilities enable attackers on the network path to read data in transit and impersonate allow-listed Node IDs to fetch private repositories.
- ▪A backward-compatible fix is not feasible due to the lack of version negotiation features, requiring a major version bump for the resolution.
- ▪Users are instructed to stop seeding private repositories and rotate any credentials or keys that may have been exposed.
2 outlets in our directory ran this story, first to last over 2 hours. All of the coverage we found sits in one bucket: centre. That one-sidedness is itself worth noticing.
- ▪ Critical security vulnerabilities in the Radicle network protocol — LWN.net (Linux Weekly News)
Hacker News (Front Page) files mainly under programming. We currently carry 2,051 of its stories. Top-voted stories on Hacker News.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | Radicle |
| Canonical URL | https://radicle.dev/2026/09/23/disclosure-of-vulnerability-in-network-protocol |
| Publication time | Wed, 23 Sep 2026 15:23:05 +0000 |
| Retrieval time | 2026-09-23T15:59:30.869Z |
| Last seen | 2026-09-23T15:59:30.869Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | hXYCCeP4cxrQ · 2 stories |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
Radicle is a peer-to-peer, local-first code collaboration stack built on Git. Disclosure of Vulnerability in the Network Protocol 23.09.2026 Summary What happened? Two critical security vulnerabilities in the network protocol used by Radicle nodes were reported. Which versions are affected? All versions of Radicle that were released to date are vulnerable. What is the issue? Network traffic between nodes is not encrypted and not authenticated. Authentication of repository contents via Signed References still detects if attackers along the network path between two nodes modify objects in transit. Thus, the main concern is information leakage, i.e., attackers along the network path between two nodes reading objects in transit.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at Radicle.