Radicle Urges Immediate Action Amid Critical Network Security Vulnerabilities
September 23, 2026
The disclosure credits Konstantinos Maninakis and cryptocode for reporting the vulnerabilities, and Radicle is outlining an upgrade path that acknowledges the breaking network change and storage compatibility considerations.
Public repositories are less risky for information leakage, while private repositories face significant risk and require immediate action.
The vulnerabilities include plain-text network traffic lacking confidentiality and broken peer authentication that can allow impersonation, potentially enabling access to private repositories on demand.
Radicle disclosed two critical security vulnerabilities in its network protocol that affect all released versions and expose data in transit between nodes.
Because the fixes involve protocol changes, the networking stack will be replaced with iroh, requiring a major version release and creating upgraded and non-upgraded clusters during the transition.
Users should stop using and seeding private repositories until a fix is released, and rotate any credentials or tokens that may have been exposed.
Summary based on 1 source
Get a daily email with more Tech stories
Source

• Sep 23, 2026
Disclosure of Vulnerability in the Network Protocol