Report Security Issues¶
To report a security issue in a WSO2 product, service, or open-source project, use one of the confidential channels below. Reports are reviewed by a small internal security team and treated with the highest priority and confidentiality.
Before reporting, see the Vulnerability Reporting Guidelines for the preparation steps, the disclosure rules, and what to include in the report. Eligible reporters may receive recognition and a reward through the Reward and Acknowledgement Program.
Security mailing lists¶
Independent security researchers and community users should submit through the confidential security mailing list that matches the scope of the finding. Each list accepts encrypted submissions; use the GPG key listed alongside.
| Scope | Email Address | GPG Key |
|---|---|---|
| Security issues relevant to SaaS Products | [email protected] | 5A40 1772 ED46 127D 197B 00AB 754F 670C 1845 8E05 PUBLIC KEY |
| Security issues relevant to Ballerina | [email protected] | AC48 3C56 C0A0 6020 4BBE F3E4 182F 3F21 255F CCE9 PUBLIC KEY |
| Any other security issues relevant to WSO2 | [email protected] | CB9B 0914 3E92 AE33 DFEA 5026 E251 CB08 CB61 38F2 PUBLIC KEY |
WSO2 Support Portal¶
WSO2 subscription customers may submit security issues either through the mailing list above or by opening a confidential ticket on the WSO2 Support Portal.
Confidentiality¶
These channels are restricted to WSO2's internal security team, the security champions of product, service, and open-source project teams, and a small set of leadership roles. All reports are handled in confidence.