<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://pbs.proxmox.com/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Security_Reporting</id>
	<title>Security Reporting - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pbs.proxmox.com/mediawiki/index.php?action=history&amp;feed=atom&amp;title=Security_Reporting"/>
	<link rel="alternate" type="text/html" href="https://pbs.proxmox.com/mediawiki/index.php?title=Security_Reporting&amp;action=history"/>
	<updated>2026-04-26T04:31:55Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://pbs.proxmox.com/mediawiki/index.php?title=Security_Reporting&amp;diff=78&amp;oldid=prev</id>
		<title>Tlamprecht: Created page with &quot;Proxmox Server Solutions takes security seriously. As such, we&#039;d like to know when a security bug is found so that it can be fixed and disclosed in a timely manner.  Note that...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pbs.proxmox.com/mediawiki/index.php?title=Security_Reporting&amp;diff=78&amp;oldid=prev"/>
		<updated>2022-09-12T07:23:17Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;Proxmox Server Solutions takes security seriously. As such, we&amp;#039;d like to know when a security bug is found so that it can be fixed and disclosed in a timely manner.  Note that...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Proxmox Server Solutions takes security seriously.&lt;br /&gt;
As such, we&amp;#039;d like to know when a security bug is found so that it can be fixed and disclosed in a timely manner.&lt;br /&gt;
&lt;br /&gt;
Note that we only support the latest point release, where the version is not yet EOL (End of Life). So, before reporting, please verify that the issue is present in a release that is still supported.&lt;br /&gt;
For that, consider the following support timeline tables:&lt;br /&gt;
&lt;br /&gt;
* Proxmox VE: https://pve.proxmox.com/pve-docs/chapter-pve-faq.html#faq-support-table&lt;br /&gt;
* Proxmox Backup Server: https://pbs.proxmox.com/docs/faq.html#how-long-will-my-proxmox-backup-server-version-be-supported&lt;br /&gt;
* Proxmox Mail Gateway: https://pmg.proxmox.com/pmg-docs/pmg-admin-guide.html#faq-support-table&lt;br /&gt;
&lt;br /&gt;
== Contact ==&lt;br /&gt;
&lt;br /&gt;
Please report security bugs to the Proxmox security team by email at &amp;lt;[mailto:security@proxmox.com security@proxmox.com]&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
Include all relevant information required to reproduce the issue.&lt;br /&gt;
&lt;br /&gt;
Any exploit code is considered helpful - we will treat such samples as private and won&amp;#039;t publish them.&lt;br /&gt;
If you or your organization already assembled a fix and has signed [https://pve.proxmox.com/wiki/Developer_Documentation#Software_License_and_Copyright our CLA] please send that along as patch, as that can speed up the process considerably.&lt;br /&gt;
&lt;br /&gt;
Please send plain text emails without attachments where possible.&lt;br /&gt;
It is much harder to have a context-quoted discussion about a complex issue if all the details are hidden away in attachments.&lt;br /&gt;
&lt;br /&gt;
We will normally send out an initial confirmation mail about the reception of a report within the next (Austrian) business day.&lt;br /&gt;
&lt;br /&gt;
If you must send highly confidential information you may use the following public GPG key, with fingerprint &amp;lt;code&amp;gt;E679 2AA6 98E1 1855 375A  B9E3 5D0C BD43 61F2 04C5&amp;lt;/code&amp;gt; to encrypt the message.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
pub   rsa4096 2022-09-01 [expires: 2032-08-29]&lt;br /&gt;
      E6792AA698E11855375AB9E35D0CBD4361F204C5&lt;br /&gt;
uid                      Proxmox Security Team &amp;lt;security@proxmox.com&amp;gt;&lt;br /&gt;
&lt;br /&gt;
-----BEGIN PGP PUBLIC KEY BLOCK-----&lt;br /&gt;
&lt;br /&gt;
mQINBGMQ2moBEACiyToARfkvOCeCTB8f5vVFSBJ5Shh7RUSXt4UQLa/FMjFKp9ZA&lt;br /&gt;
YV6n3kcLkLOxZGFMruI7zlQD31tu2pApPP8NKCjeZwg2dqS72F29xQdDDY4UlxjX&lt;br /&gt;
T5UckNtKY6Uqlarrd2cMFL5bUsM47LaTt/EtBFdhl4YiW2i6Z7FtR2MKZtEZnb3s&lt;br /&gt;
x31XrWUh9mGyJ+gZyHmNOn9HrUf4LCo+HDqirAMiuJiVnCHVIbhOgVf1jHNuYfKU&lt;br /&gt;
cyaxXbhfqdWuWkc0K7+2+ClaiKrifEbQ56SbnrYEmCOl2WB1vF4GuPCN4rRByLBa&lt;br /&gt;
cfI1GQlChZtXBpDKwZYTm4OxUfouRb7F1Dc19zejqSUHO+rCKseXMM45YSs48jJU&lt;br /&gt;
LYjSa7FQTaHjpN1M7Zoz/P5bgbBd4pAXF5BdBekuQRc0P3VzTLISDXKTSJ6mvTk3&lt;br /&gt;
hcMk7Wr6KGeUt0ftP1AblRvGdeQ8w8VVgEqc+yAozFguRTUmpvEo+714Ak+MyFm8&lt;br /&gt;
FXMdwRetnJ7IVsPxaQIzHjWoWPGAKhXecmi/uLC8caU4+vlNsFT87GMz7mOuyDhK&lt;br /&gt;
n+8fIbn7IRvuJXjQB73eQS+My+9jLGK6UjIAz8MmA0LumZ6sfunevAyDqSc/lGkc&lt;br /&gt;
Jcore+Qb3AC0excFCbgND31+i/iJHXIbSe7Fra/9zN+GodAjnXnQn2HHLQARAQAB&lt;br /&gt;
tCxQcm94bW94IFNlY3VyaXR5IFRlYW0gPHNlY3VyaXR5QHByb3htb3guY29tPokC&lt;br /&gt;
VAQTAQoAPhYhBOZ5KqaY4RhVN1q5410MvUNh8gTFBQJjENpqAhsvBQkSzAMABQsJ&lt;br /&gt;
CAcCBhUKCQgLAgQWAgMBAh4BAheAAAoJEF0MvUNh8gTFkvwP/0B+RNoTHbMRaaNz&lt;br /&gt;
RGl6sAshc6DOxCqxjCibWfiRr0pXADzL+NdNDyRsPY+i9Q+QQukF1PvPx9HBf4bu&lt;br /&gt;
3gcJ5cVbi9/nYH4BiWNM0z8HDoYto3PpCDLK944dbUV4OfnYp3rp8GkMLq7CUB9l&lt;br /&gt;
Hji7m63bGXuB+Rc/iEFoNKXtYh7fZIq8WiWDwOVdyslc/wC3RjbEPhXts3SHntXl&lt;br /&gt;
y5Qdr1WEcFLW6GjfMUeJR5Oy3XccfKVPKhoNgGqrUqaN0PCQsQWCJ6czc0uGzP1p&lt;br /&gt;
EFu8ct5C71/iZ0eak84SRf8cQxN2gwTb40rAkNIq3msCT8oaSc2vZQ0X+S0+Abq4&lt;br /&gt;
5YOkNlCQB9f7XOKCTajjiYlElXw4H4X0uO4uKQbCBeXBI3HktivpQ1rEadXJiCl/&lt;br /&gt;
eayeN6nBdOkupev73g3xVXCyI+QFd4IVufTqi1m857f3dNv/suHLj/Upd6q8rmqq&lt;br /&gt;
M5s+e+3qUiAhEoB7sSCsXCh60SnDGYHsRa33F2Fz8pPpmuboW55z8OOaAgrVt/TB&lt;br /&gt;
oZJdTzUCx77HXKMvlulZkjfuWzOB+qh6CR+bzNWzVyD3yYpNbH0UF+vBZ3sYb7Al&lt;br /&gt;
/rAorlMz/gybSdrilHoxz2w9grcrTg6jk/dLwesCm1bzJKznEFVHQv/Mk+Kt+ZQ4&lt;br /&gt;
/pfx41HDLtAoGfQBWxjy8n2Qrk8l&lt;br /&gt;
=UVAu&lt;br /&gt;
-----END PGP PUBLIC KEY BLOCK-----&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Additionally available to download in binary format from [https://enterprise.proxmox.com/debian/security-report.gpg.pub the enterprise CDN].&lt;br /&gt;
&lt;br /&gt;
== Disclosure and Embargoed Information ==&lt;br /&gt;
&lt;br /&gt;
Once a robust fix has been developed, the release process starts.&lt;br /&gt;
Proxmox Server Solutions will release fixes for publicly undisclosed bugs as soon as they become available, but we can hold back sensible information from commits and change logs at the requests of the reporter or an affected party.&lt;br /&gt;
&lt;br /&gt;
== CVE assignment ==&lt;br /&gt;
&lt;br /&gt;
The security team does not normally assign CVEs, nor do we require them for reports or fixes, as this can needlessly complicate the process and may delay the bug handling.&lt;br /&gt;
&lt;br /&gt;
We would still appreciate if you notify us about any assigned ID, for coordination and communication purpose.&lt;/div&gt;</summary>
		<author><name>Tlamprecht</name></author>
	</entry>
</feed>