Security
Disclosure
Policy
Thank you for your discretion
Independent security researchers make an important contribution to the security of our projects. We greatly appreciate their work. To ensure the security of our users, we strongly endorse the principles of Coordinated Vulnerability Disclosure (CVD) and adhere to them strictly.
How to report a vulnerability
If you believe you have discovered a security vulnerability in our projects, please report it directly to us at: bundesmessenger@bwi.de.
For confidential communication, we recommend encrypting your findings with our PGP key.
So that we can assess and remediate the issue efficiently, your initial report must contain a clear and comprehensive description of the vulnerability, including steps to reproduce it. We ask you to treat all findings strictly confidential and not to share them publicly until we have thoroughly reviewed the issue and agreed on a timeline.
Our process
If you submit a valid security report, you can expect the following from our team:
- Prompt response: Security incidents are our top priority. We will acknowledge receipt of your report, verify the issue and provide initial feedback or ask follow-up questions within 5 working days..
- Remediation timeline: We will work with you to define a disclosure timeline. Our standard goal is to provide a fix within 90 days. Depending on the complexity of the issue, this period may be extended on a case-by-case basis (usually up to 120 days).
- Transparency: WIf a vulnerability affects our user base, we are committed to informing our customers and the wider community transparently.
- Delayed disclosure for severe issues: For critical vulnerabilities that are exceptionally disruptive or trivially exploitable, we may request an embargo on technical details of up to 30 days after a patch is released. This ensures our users have sufficient time to update their systems safely.
- Public disclosure: Once we have fixed the vulnerability (or formally accepted the risk), we will notify you, and you are then free to publish your research findings.
Non-qualifying vulnerabilities
The following vulnerabilities / IT security issues are outside the scope of this Security Disclosure Policy:
- Attacks requiring physical access to a user’s device or network.
- Forms lacking CSRF tokens (exception: severity exceeds level 5 of the Common Vulnerability Scoring System (CVSS)).
- Missing security headers that do not directly lead to an exploitable vulnerability.
- Use of a library known to be vulnerable or publicly compromised (without active proof of exploitability).
- Reports from automated tools or scans without explanatory documentation.
- Social engineering against individuals or organizations of BWI, the Bundeswehr and their contractors.
- Denial-of-service attacks (DoS/DDoS).
- Bots, spam, mass registrations.
- Submission of best-practice recommendations (e.g. certificate pinning, security headers).
- Use of vulnerable or “weak” cipher suites / ciphers.
- Sales activities aimed at promoting or selling security products or services.