Security & Coordinated Vulnerability Disclosure
The security of OpenCelium and the protection of our users are a top priority for us.
We are continuously improving OpenCelium and regularly review the security of our software and its dependencies. If you discover a security vulnerability in OpenCelium, we would appreciate a responsible and coordinated report.
Report a Security Vulnerability
If you have discovered a potential security vulnerability in OpenCelium, please contact us at:
Please use this address exclusively for reports of potential security vulnerabilities and security-related issues.
Please do not report security vulnerabilities via public GitHub Issues, community forums, or other public channels. This allows us to investigate the report first and, if necessary, provide a security update.
What information should a report include?
To help us investigate and assess a report as quickly as possible, we ask that you provide the following information, if possible:
- Affected OpenCelium version
- Affected component or function
- Description of the security vulnerability
- Steps to reproduce
- Expected and actual behavior
- Possible impact of the vulnerability
- Proof of Concept (PoC), if applicable
- Relevant logs, screenshots, or other technical information
- CVE, CWE, or other references, if applicable
- Contact information for follow-up questions
The more technical information you can provide, the easier it will be for us to understand and evaluate the report.
How We Handle Security Alerts
We ask security researchers and others who discover security vulnerabilities to first give us the opportunity to investigate the report and take appropriate action.
We strive for coordinated disclosure, in which the publication of technical details is timed so that users have sufficient time to apply available security updates or implement other protective measures.
Please do not publicly disclose detailed information or proof-of-concept code regarding an unpatched vulnerability before coordinating the next steps with us.
Coordinated Disclosure
We ask security researchers and others who discover security vulnerabilities to first give us the opportunity to investigate the report and take appropriate action.
We aim for coordinated disclosure, whereby technical details are released—as far as possible—in a way that gives users sufficient time to apply available security updates or implement other protective measures.
Please do not publicly disclose detailed information or proof-of-concept code regarding an unpatched security vulnerability before coordinating the next steps with us.
Handling Reports
We treat incoming security reports as confidential and use the information provided solely for the investigation, assessment, and resolution of the reported security issue, as well as for related security and compliance processes.
We also ask reporters not to provide us with personal data, login credentials, or other confidential information that is not necessary for the analysis.
Supported Versions
Information about currently supported OpenCelium versions and their security support is published on the OpenCelium website and in the respective release and product notes.
Security updates are provided for supported versions to the extent that this is necessary and technically feasible for the respective version and the security issue in question.
Safety Information
Information about resolved and disclosed security vulnerabilities is published through our official OpenCelium channels, provided that public disclosure is possible and appropriate.
A published security advisory includes, where available and appropriate:
• Affected OpenCelium versions
• Fixed versions
• Description of the vulnerability
• Severity and impact
• A CVE reference, if applicable
• Information on the fix
• Required actions for users
Contact
Security Contact:
security@opencelium.io
Please use this contact exclusively for security-related reports.
For general questions, support requests, or product inquiries, please use the designated OpenCelium channels.