We got a report of a bug in our certificate pinning code. We confirm that this bug exists and currently does not affect f-droid.org. This bug can only be exploited when an upstream project is compromised first, and only new installations will be affected. Therefore, we consider this bug of low urgency. We're looking into the reporter's patches + thank them for their work.