Nabto Security and Support Policy
This page states how Nabto provides security updates for its products, which versions receive them and for how long. It applies to all Nabto platforms: Nabto Edge, Nabto WebRTC and Nabto 4, each with its client SDKs (software development kits), embedded SDKs, wrapper libraries and Nabto-operated hosted services, as well as Nabto applications such as Nabto Cambridge.
The policy is written to meet the obligations of the EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847): It is the statement of the support period and the type of security support that the CRA requires a manufacturer to give its users. It is also the document Nabto’s customer contracts refer to. It is a commitment to every user of a Nabto product, whether or not a contract is in place.
Policy version: 2026-09-08.
Security Updates
When a vulnerability is confirmed in a Nabto SDK, library or application, Nabto fixes it and releases the fix as a security update:
- Security updates are free of charge for every user of the product, throughout the support period.
- A security update is released as a patch release (the last number in the version,
X.Y.Z) that contains the fix and no functional changes. Adopting a security update therefore never forces new functionality on you. - Each security update is accompanied by a security advisory, see Security Advisories.
- Security updates are released without undue delay once a fix is available. Fixes for actively exploited vulnerabilities are prioritized over everything else.
- A released security update remains available for download for at least ten years after the product was first made available or for the rest of the product’s support period, whichever is longer, as CRA Article 13(9) requires.
Vulnerabilities in Nabto-operated hosted services (basestations, signaling, STUN and TURN relay and related services) are fixed by Nabto in place. Nothing needs to be installed on your side. Nabto applications distributed through app stores or as installable packages are updated through the same channel they were installed from.
Installing a security update in a product that embeds a Nabto SDK is the responsibility of the maker of that product. Nabto’s obligation is met when the update and its advisory are available and users have been notified.
Supported Release Lines
Nabto SDKs and libraries are versioned as major.minor.patch. A major version is a platform generation, for instance Nabto Edge 5 or Nabto 4. A minor release adds functionality without removing or changing existing API. A patch release contains fixes only. For SDKs still below version 1.0, the second number is treated as the minor for the purposes of this policy.
Within a supported major version, security updates are provided for these release lines:
- The current minor release always receives security updates, as a new patch release.
- The previous minor release keeps receiving security updates as patch releases for twelve months after the next minor release was published. This grace period exists so that a security fix never forces you to take a functionality update at short notice.
- Older minor releases do not receive security updates. To receive them, move to a supported minor release. Minor releases within a major version are API compatible. Moving is therefore a rebuild against the newer SDK rather than a migration. Protocol-level considerations between client and device versions are listed on the Nabto Edge Version Compatibility page.
An example: With 5.9.2 in use, a vulnerability is fixed in 5.9.3. Nabto later publishes 5.10.0 with new features, which includes the fix. When a new vulnerability is then found that affects both lines, it is fixed in 5.10.1 and, for twelve months after 5.10.0 was published, also in 5.9.4. After that period a fix is provided in the 5.10 line only.
Nabto may, at its discretion, provide security updates for release lines beyond those listed here, for example under a support agreement. This policy states the minimum.
Support Periods
Each platform receives security updates for the support period below. A support period is never shorter than five years from the date the product was first made available. An end date, once published here, is never moved earlier.
| Platform | Status | Security updates provided until |
|---|---|---|
| Nabto Edge | Active development | No end date set |
| Nabto WebRTC | Active development | No end date set |
| Nabto 4 | Maintenance: Security updates only, no new features | No end date set |
Nabto Cambridge and the Nabto-operated hosted services follow the platform they belong to.
When Nabto decides to end support for a platform, the end date is published on this page at least 24 months in advance and users with a registered security contact are notified directly. Security updates released before the end date remain available as described under Security Updates.
Security Advisories
Every security update is accompanied by a security advisory that identifies the vulnerability (with a CVE identifier where one has been assigned), the affected versions, the fixed version, the severity and any action users need to take. Advisories are published as GitHub Security Advisories on the affected repository under github.com/nabto and are listed here.
No security advisories have been published under this policy yet.
Reporting a Vulnerability
If you find a security issue in a Nabto product, please report it as described on www.nabto.com/security. That page also holds Nabto’s security contact and coordinated disclosure terms. Customers who have signed the Nabto CRA Addendum (document CNT352) have an agreed notification channel in both directions and a registered security contact that Nabto notifies directly when a vulnerability affects their products.
Changes to this Policy
Nabto may update this policy. A change never shortens a support period already published here and never removes a security update already released. Changes are listed below with the date they took effect.
- 2026-09-08: First version of the policy.
