Critical security vulnerabilities in the Radicle network protocol
The Radicle peer-to-peer code-collaboration project has disclosed two critical vulnerabilities in the network protocol used by Radicle nodes. The first flaw is that the network protocol used by Radicle " does not give the confidentiality it was expected to give ", which allows anyone who can observe the network between two nodes to read the data exchanged. The second is that peer authentication…
Radicle, a peer-to-peer code-collaboration project, has revealed two critical vulnerabilities in its network protocol. The first flaw allows the lack of confidentiality, which enables any observer to read the data exchanged between two nodes. The second issue stems from broken peer authentication, allowing attackers to impersonate Node IDs and gain access to private repositories they should not be able to read.
When these two flaws are combined, an attacker in the network path can not only read the exchanged data but also fetch the entire repository using a Node ID they have observed. The real threat lies in anyone on the path between your node and its syncing node, and no setting or allow-list can provide protection against this. The disclosure comes before a security update, urging immediate action since no fix can undo past exposures.
Workarounds are available for immediate use, while a major update is being prepared that will be backward-incompatible.
Written by urgent.news from LWN's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.