In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each other based on certificate verification.
https://github.com/Seanland/snyk-vuln-hunter
https://github.com/advisories/GHSA-hpf7-4c2g-9chf