# Radicle Discloses Critical Flaws Exposing Private Repositories in Plain Text

DevFeed: [Radicle Discloses Critical Flaws Exposing Private Repositories in Plain Text](<https://devfeed.tech/articles/radicle-discloses-critical-flaws-exposing-private-repositories-in-plain-text-61385.md>)

Original publisher: [Read original article](<https://www.infoq.com/news/2026/09/radicle-network-vulnerabilities/>)

Author: Olimpiu Pop

Published: 2026-09-28T14:14:00Z

Content type: news

Language: en

Sources: [InfoQ](<https://devfeed.tech/sources/infoq.md>)

Topics: [Security research](<https://devfeed.tech/topics/security-research.md>), [Security](<https://devfeed.tech/topics/security.md>), [SSL](<https://devfeed.tech/topics/ssl.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [common-vulnerabilities-and-exposures](<https://devfeed.tech/tags/common-vulnerabilities-and-exposures.md>), [critical](<https://devfeed.tech/tags/critical.md>), [development](<https://devfeed.tech/tags/development.md>), [network](<https://devfeed.tech/tags/network.md>), [news](<https://devfeed.tech/tags/news.md>), [peer-to-peer](<https://devfeed.tech/tags/peer-to-peer.md>), [peer-to-peer-communication](<https://devfeed.tech/tags/peer-to-peer-communication.md>), [radicle-network-vulnerabilities](<https://devfeed.tech/tags/radicle-network-vulnerabilities.md>), [rust](<https://devfeed.tech/tags/rust.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [sockets](<https://devfeed.tech/tags/sockets.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

Radicle disclosed two critical vulnerabilities in its peer-to-peer wire protocol that expose private repository data in cleartext and allow attackers to impersonate allow-listed nodes. The reported causes include discarded Noise handshake cipher states and an authentication validation flaw. The article says mitigation requires a new, incompatible protocol and recommends halting clearnet private-repository operations until an overhaul is available.

## Source excerpt

Radicle has identified two critical security vulnerabilities in its wire protocol, compromising confidentiality across all node releases. Attackers can access private repository data in cleartext and impersonate nodes. Due to architectural flaws, immediate halting of clearnet operations is advised. Fixes will require a shift to a new protocol (Iroh), creating backward incompatibility issues. By Olimpiu Pop