Skip to content
Radicle Protocol Vulnerabilities Expose Private Data

Radicle Protocol Vulnerabilities Expose Private Data

First seen 28 Sep 2026, 16:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 16:08 UTC
  • •Two critical vulnerabilities expose private repository data in cleartext.
  • •All versions of radicle-node are affected, with no current patch available.
  • •Immediate action is recommended to secure communications using VPNs or SSH tunnels.

Radicle has disclosed two critical vulnerabilities in its wire protocol that allow attackers to read private repository data in cleartext and impersonate nodes. The flaws stem from a failure to maintain cipher states after a Noise handshake, resulting in unencrypted communication over TCP sockets. This affects all versions of radicle-node released to date, including the latest 1.10.3. The vulnerabilities were identified by engineer Kostis Maninakis and have prompted recommendations to halt clearnet operations for private repositories. The lack of version negotiation capabilities prevents a backward-compatible fix, necessitating a major architectural overhaul. Users are advised to tunnel connections through secure methods like WireGuard or SSH to mitigate risks. The vulnerabilities have not yet been patched, and a RustSec advisory may follow.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-23
Vulnerability disclosure by Kostis Maninakis
Kostis Maninakis reported critical flaws in Radicle's wire protocol that expose private data.
maninak.com
2026-09-28
InfoQ reports on Radicle vulnerabilities
InfoQ published details on the vulnerabilities and recommended halting clearnet operations for private repositories.
Infoq

More articles in this cluster (2)

Following this threat?

Track WireGuard in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed