Radicle Discloses Critical Flaws Exposing Private Repositories in Plain Text
Critical wire-protocol flaws expose private repos in plaintext across all Radicle nodes. Fix requires migration to new protocol—backward incompatible.

Why it matters
Radicle's distributed repository network disclosed two critical vulnerabilities allowing attackers to read private data and impersonate nodes. The fix necessitates a protocol shift to Iroh, forcing nodes offline during transition and breaking compatibility—a material operational risk for any deployment relying on Radicle's peer-to-peer architecture.
The key facts
6 to knowTwo critical vulnerabilities in Radicle wire protocol affecting all node releases
Flaws allow plaintext access to private repository data and node impersonation
Architectural issues require halt of clearnet operations pending fix
Fix requires migration to new protocol (Iroh), creating backward incompatibility
Published: Mon Sep 28 2026 (InfoQ)
Source: Olimpiu Pop reporting
Go to the source
InfoQ AI/MLinfoq.com
Publisher excerpt: Radicle has identified two critical security vulnerabilities in its wire protocol, compromising confidentiality across all node releases. Attackers can access private repository data in cleartext and impersonate nodes. Due to architectural flaws, immediate halting of clearnet operations is advised.…