Skip to content

Report Security Issues

To report a security issue in a WSO2 product, service, or open-source project, use one of the confidential channels below. Reports are reviewed by a small internal security team and treated with the highest priority and confidentiality.

Before reporting, see the Vulnerability Reporting Guidelines for the preparation steps, the disclosure rules, and what to include in the report. Eligible reporters may receive recognition and a reward through the Reward and Acknowledgement Program.

Security mailing lists

Independent security researchers and community users should submit through the confidential security mailing list that matches the scope of the finding. Each list accepts encrypted submissions; use the GPG key listed alongside.

Scope Email Address GPG Key
Security issues relevant to Choreo [email protected] E244 7A59 F1E0 9369 5CBA 3195 FF67 8AD2 84F9 6B9A
PUBLIC KEY
Security issues relevant to WSO2 Identity Platform [email protected] 7EFB 2075 2A3D 65D0 0C15 33F1 79FD 52B8 1D17 AE48
PUBLIC KEY
Security issues relevant to Open Healthcare [email protected] 987D 5905 4458 6364 B901 B13D 0AB1 AB05 A68A 1BBF
PUBLIC KEY
Security issues relevant to Ballerina [email protected] 0168 DA26 2989 0DB9 4ACD 8367 E683 061E 2F85 C381
PUBLIC KEY
Any other security issues relevant to WSO2 [email protected] CB9B 0914 3E92 AE33 DFEA 5026 E251 CB08 CB61 38F2
PUBLIC KEY

WSO2 Support Portal

WSO2 subscription customers may submit security issues either through the mailing list above or by opening a confidential ticket on the WSO2 Support Portal.

Confidentiality

These channels are restricted to WSO2's internal security team, the security champions of product, service, and open-source project teams, and a small set of leadership roles. All reports are handled in confidence.