This policy applies to all Nabto repositories that do not provide their own
SECURITY.md.
Preferred: report it through GitHub. On the repository's Security tab, open Advisories and click Report a vulnerability. That opens a private, tracked thread with the Nabto security response team. Private vulnerability reporting is enabled on our public repositories.
If the issue is not tied to a repository published here, or you would rather use email, write to vulnerabilities@nabto.com.
Please do not open a public GitHub issue, pull request or discussion for a security vulnerability.
If you have evidence that the vulnerability is being actively exploited against
real deployments, put [ACTIVE EXPLOITATION] at the start of the advisory
title, or at the start of the email subject if you are using email. We
fast-track those.
Response times, what to include in a report and how we handle disclosure are documented on the website:
https://www.nabto.com/security-vulnerability-reporting/
Machine-readable contact details: https://www.nabto.com/.well-known/security.txt (RFC 9116).
Supported versions differ per product; see the release notes or README of the individual repository.