This page is the entry point for everything about security in Nabto’s products: How to report a vulnerability to us, how long we provide security updates and where we publish advisories. Our security contact is also published in machine-readable form at /.well-known/security.txt. For how the products themselves are designed to be secure, see who you need to trust.
What to do if you find a security issue
If the issue is in code we publish on GitHub, the fastest route is the Report a vulnerability button on that repository’s Security tab, under Advisories. It opens a private, tracked thread with our security response team and it is our preferred channel.
If the issue is not tied to one of those repositories, or you would rather use email, write to [email protected].
Please use one of these two channels rather than a public one such as a GitHub issue or a mailing list, so we can fix the problem before it is described publicly.
We acknowledge and begin analysis of every report within one week. Reports of active exploitation are handled faster: see below.
If the vulnerability is being actively exploited
If you have evidence that someone is already exploiting the vulnerability against real deployments, mark it so we see it immediately: put [ACTIVE EXPLOITATION] at the start of the advisory title, or at the start of the email subject if you are using email. We acknowledge these reports within 24 hours.
This matters beyond our own response. Under the EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847), a manufacturer must send an early warning about an actively exploited vulnerability to the authorities within 24 hours of becoming aware of it. Your report is what starts that clock, so please do not wait to polish it.
What to include
A report is easiest to act on when it tells us:
- which Nabto product or SDK is affected and which version
- what an attacker can achieve
- how to reproduce it, step by step
- whether you have seen it exploited
- how you would like to be credited if we publish an advisory
Send what you have. An incomplete report is better than a late one and we will come back with questions.
What happens next
- We acknowledge your report within the times above.
- Our security response team analyses it and tells you whether we can reproduce the issue and how we assess its severity.
- We keep you updated while we work on a fix and let you know when it ships.
- We ask that you do not describe the vulnerability publicly before we have released a fix and published our advisory. We coordinate the timing with you and will try to accommodate your plans. The decision on when Nabto publishes its advisory is ours. We aim to publish within 90 days of your report and will tell you if we need longer.
Security updates and supported versions
When a vulnerability is confirmed in a Nabto SDK, library or application, we fix it and release the fix as a security update. Security updates are free of charge for everyone who uses the product. They are shipped as patch releases that contain the fix and nothing else, so you can adopt them without taking on new functionality. Vulnerabilities in the Nabto-operated hosted services are fixed by us in place; there is nothing for you to install.
How long each product receives security updates, and which release lines a fix is provided for, is set out in the Nabto Security and Support Policy in the developer documentation. That policy is the reference for the support period the CRA requires a manufacturer to state. It is also the document our customer contracts point to.
Security advisories
Every security update is accompanied by an advisory that describes the vulnerability, the affected versions, the fixed version and any action you need to take. Advisories are published as GitHub Security Advisories on the affected repository under github.com/nabto and are listed on the Security and Support Policy page. Customers with a signed CRA addendum are also notified directly at their registered security contact.