Skip to content

Security policy

Found a vulnerability? Report it privately.

A SIP endpoint parses hostile input for a living. Reports are welcome, handled in private, and credited. Do not open a public issue for a vulnerability.

How to report

Use the contact form with the subject Security report. It reaches the maintainer alone. No e-mail address is needed from either side to start.

Report a vulnerability

Say which version or commit you tested, how to reproduce it, and what an attacker gains. Once the source repository is public, its private vulnerability reporting becomes a second route under the same commitments.

  1. 01

    Acknowledgement

    The maintainer confirms the report arrived and is being read.

  2. 02

    Triage

    The report is reproduced against the code it names, or you are asked for what is missing; scope is checked and a severity assigned.

  3. 03

    Fix

    A fix is written and tested the way every change is, through the release gate and the lab where signalling or media is touched, before anything about the report becomes public.

  4. 04

    Coordinated disclosure

    The report stays private until a fix has shipped or the disclosure deadline is reached, whichever comes first. A different timeline is agreed in writing before it applies.

  5. 05

    Advisory and CVE

    A security advisory is published once disclosure is due, naming the affected and the fixed versions; a CVE ID is requested for anything that qualifies.

  6. 06

    Credit

    You are named in the advisory, unless you ask to stay anonymous or to be named differently.

Time commitments

The maintainer's commitments to every reporter. A report that needs longer to fix correctly is not rushed past them: you are told why, with a revised estimate, before a deadline passes.

FromToWithin
Report received Acknowledgement 3 business days
Acknowledgement Triage: reproduced, scoped, severity assigned 10 business days
Triage A fix, for critical or high severity 30 days
Triage A fix, for medium or low severity No fixed deadline; tracked to closure, not dropped
Acknowledgement Public disclosure, fixed or not 90 days, unless both sides agree in writing to extend

Scope

In scope

Anything reachable from the network, and the parser especially:

  • memory safety, or a panic reachable from a received message, in any crate
  • a hang or unbounded allocation triggered by a crafted message
  • authentication that accepts what it should reject, including digest verification and SRTP key handling
  • credentials, keys or media leaking into logs or error messages
  • media accepted from a source that should not be able to inject it

Out of scope

  • denial of service that needs traffic volume rather than a crafted message
  • findings against a peer implementation Sipral interoperates with: report those to their maintainers
  • anything that requires the attacker to already control the process

Supported versions

Before 1.0, the latest version. After 1.0, the current minor version and the one before it.