Reporting a Security Vulnerability

This page is our policy on coordinated vulnerability disclosure as required by Article 13 and Annex I Part II of the Cyber Resilience Act, Regulation (EU) 2024/2847. It applies to every application and website published by Dirk Holtwick.

Where to report

Email: confidential@holtwick.de

This address is the single point of contact for security reports. It is monitored by Dirk Holtwick personally.

For sensitive details please encrypt your message with our public PGP key. The same information in machine-readable form is available at /.well-known/security.txt according to RFC 9116.

Please do not use the public support channels, the issue tracker or social media for a vulnerability report.

No bug bounty

We do not operate a bug bounty programme. Reports are voluntary and we offer no payment, voucher, swag or reward of any kind in return, neither before nor after a fix. Please only report a finding if you are happy to do so on that basis.

Automated scanner output, mass-mailed reports and reports sent with an invoice or a request for payment attached will be closed without a reply.

What to include

The more precise the report, the faster the fix. Useful:

  • Affected product and version, and the operating system you used.
  • What an attacker can achieve, and what access they need to start.
  • Steps to reproduce, ideally minimal. A short screen recording or a sample file often says more than a paragraph.
  • Whether the finding is already public or known to third parties.

German and English are both fine.

What happens next

StepTimeline
Acknowledgement of receiptwithin 5 working days
Initial assessment, whether we can reproduce it and how we rate the severitywithin 14 days
Fix in a released versiondepends on severity, as fast as reasonably possible
Public disclosureonce the fix is available to users

We keep you informed while we work on it and we tell you when the fix ships. Once a security update is available we publish information about the fixed vulnerability, its severity and its impact — in the release notes, and where a CVE identifier exists, alongside it.

If we conclude that a report does not describe a vulnerability, we will tell you why.

Should a vulnerability turn out to be actively exploited, we are obliged to report it to ENISA and to the German CSIRT within 24 hours under Article 14 of the Cyber Resilience Act. Your report may become part of that notification. We do not pass on your name or contact details unless you tell us we may.

Credit

If you would like to be credited by name once the fix is public, please include that in your report and let us know how. It’s perfectly fine to remain anonymous as well.

Please do not

We will not pursue legal action over a report made in good faith and in line with this policy. Staying within following lines is what makes a report one made in good faith:

  • Only work on your own data, your own account and your own installation.
  • Do not access, alter or delete data belonging to other people, and stop as soon as you can see personal data.
  • No denial of service, no load or stress testing, no spam, no social engineering of us or of our customers.
  • Do not use the finding beyond what is needed to demonstrate it, and do not sell or pass it on.
  • Give us time to fix the issue before you publish. If you have your own disclosure deadline, name it in the first message so we can plan for it.

Nothing on this page grants permission to attack third-party services we happen to use.