# Radicle warns private repositories are exposed by two network flaws

_Published Wednesday, September 23, 2026 at 1:08 PM EDT · Security, Infrastructure · Latest · Tier 1 — Major_

![Radicle warns private repositories are exposed by two network flaws — Primary](https://radicle.dev/assets/images/og-card.png)

Radicle disclosed two critical flaws affecting every version of its peer-to-peer code collaboration software and advised users to stop sharing private repositories over its network until a fix is released. Traffic between nodes travels without encryption, allowing someone on its network path to read exchanged data. A separate handshake flaw can let an attacker impersonate an authorized node and fetch a private repository.

Radicle says the flaws can work together when an observer learns authorized node IDs from traffic. It advises users to treat previously transmitted private repositories as leaked and rotate any exposed credentials. The planned network-protocol replacement will break compatibility between upgraded and older nodes; signed references still protect repository contents against forgery.

## Sources

- [radicle.dev](https://radicle.dev/2026/09/23/disclosure-of-vulnerability-in-network-protocol)

---
Canonical: https://techandbusiness.org/newswire/b1y0VPr7uuqPeGYTCgWZly
Published: 2026-09-23T17:08:08.446Z
Story chronology: 2026-09-23T15:23:05.000Z
Retrieved: 2026-09-23T18:50:02.345Z
Publisher: Tech & Business (techandbusiness.org)
