Security policy
Found a vulnerability? Report it privately.
How to report
Use the contact form with the subject Security report. It reaches the maintainer alone. No e-mail address is needed from either side to start.
Report a vulnerabilitySay which version or commit you tested, how to reproduce it, and what an attacker gains. Once the source repository is public, its private vulnerability reporting becomes a second route under the same commitments.
- 01
Acknowledgement
The maintainer confirms the report arrived and is being read.
- 02
Triage
The report is reproduced against the code it names, or you are asked for what is missing; scope is checked and a severity assigned.
- 03
Fix
A fix is written and tested the way every change is, through the release gate and the lab where signalling or media is touched, before anything about the report becomes public.
- 04
Coordinated disclosure
The report stays private until a fix has shipped or the disclosure deadline is reached, whichever comes first. A different timeline is agreed in writing before it applies.
- 05
Advisory and CVE
A security advisory is published once disclosure is due, naming the affected and the fixed versions; a CVE ID is requested for anything that qualifies.
- 06
Credit
You are named in the advisory, unless you ask to stay anonymous or to be named differently.
Time commitments
The maintainer's commitments to every reporter. A report that needs longer to fix correctly is not rushed past them: you are told why, with a revised estimate, before a deadline passes.
| From | To | Within |
|---|---|---|
| Report received | Acknowledgement | 3 business days |
| Acknowledgement | Triage: reproduced, scoped, severity assigned | 10 business days |
| Triage | A fix, for critical or high severity | 30 days |
| Triage | A fix, for medium or low severity | No fixed deadline; tracked to closure, not dropped |
| Acknowledgement | Public disclosure, fixed or not | 90 days, unless both sides agree in writing to extend |
Scope
In scope
Anything reachable from the network, and the parser especially:
- memory safety, or a panic reachable from a received message, in any crate
- a hang or unbounded allocation triggered by a crafted message
- authentication that accepts what it should reject, including digest verification and SRTP key handling
- credentials, keys or media leaking into logs or error messages
- media accepted from a source that should not be able to inject it
Out of scope
- denial of service that needs traffic volume rather than a crafted message
- findings against a peer implementation Sipral interoperates with: report those to their maintainers
- anything that requires the attacker to already control the process
Supported versions
Before 1.0, the latest version. After 1.0, the current minor version and the one before it.