Security Contact

Use this page to report potential security vulnerabilities and to access information about our reporting channels, coordinated vulnerability disclosure policy, and other security-related resources.

Vulnerability Report

Use the form below to describe a potential security issue as clearly and structurally as possible. Please only submit information that is necessary for assessment, reproducibility, and follow-up questions.

Fields marked with * are required. All contact details, including your email address, are optional.

Tell us about the Vulnerability

Please provide a Proof of Concept or reproducible steps if available.
What does an attacker gain that the attacker did not have before?
Be specific about tools and versions you used.

What are your disclosure plans?

Have you already reported this vulnerability to other vendors or organizations? (optional)
Is this vulnerability being publicly discussed? (optional)
Is there evidence that this vulnerability is being actively exploited? (optional)
I plan to publicly disclose this vulnerability (optional)
Please include the time and time zone, for example: 2026-10-15, 10:00 UTC+2.

What are your contact details?

All contact details are optional. You may submit the report anonymously.

Without an email address, we cannot ask follow-up questions or send status updates.
Paste an ASCII-armored public key or provide a direct URL.
May we provide your contact information to third parties? (optional)
Do you want to be publicly acknowledged in a disclosure? (optional)

Any Additional Information?

Please do not submit unnecessary personal data or unrelated sensitive information.

Additional Information

Information about how we handle incoming reports and recognitions can be found on our Hall of Fame page:

https://www.erminas.com/hall-of-fame/

Disclosure Policy

Our coordinated vulnerability disclosure policy describes expectations, reporting channels, and our general handling of incoming reports:

https://www.erminas.com/disclosure-policy/

Machine-Readable Security Information

Our machine-readable security contact information is published at the following location:

https://erminas.de/.well-known/security.txt

OpenPGP Keys

Public OpenPGP keys for encrypted communication are published here:

  • https://www.erminas.com/openpgp-key_psirt.asc
  • https://www.erminas.com/openpgp-key_csirt.asc

Notice

This page is intended exclusively for reporting potential security vulnerabilities and coordinating related disclosures. It does not replace general support, sales, or contact channels.