ASF Security Team
Skip to Main Content
The Apache Software Foundation
Apache 20th Anniversary Logo

ASF Security Team

The Apache Security Team guides Apache projects on security issues and coordinates the handling of all security vulnerabilities. The team is a CVE Numbering Authority (CNA) covering all Apache projects and is the only group able to allocate IDs to Apache Software Foundation project issues. Advisories are published per project, and may be reviewed via the project advisories.

Reporting a vulnerability

We strongly encourage you to report potential security vulnerabilities to one of our private security mailing lists first, before disclosing them in a public forum.

A list of security contacts for Apache projects is available. If you can't find a project-specific security e-mail address and you have an undisclosed security vulnerability to report, use the general security address below.

Only use the security contacts to report undisclosed security vulnerabilities in Apache projects and manage the process of fixing such vulnerabilities. We cannot accept regular bug reports or other security-related queries at these addresses. We will ignore mail sent to these addresses that does not relate to an undisclosed security problem in an Apache project.

Also note that the security team handles vulnerabilities in Apache projects, not running ASF services. Send reports of vulnerabilities in ASF services to root@apache.org. (This includes issues with apache.org websites)

The general security mailing list address is: security@apache.org. This is a private mailing list.

Please send one plain-text, unencrypted, email for each vulnerability you are reporting. We may ask you to resubmit your report if you send it as an image, movie, HTML, or PDF attachment when you could as easily describe it with plain text.

Issues not considered as security vulnerabilities

These are things that we are well aware of, and have been reported to us many times, but we do not class as a security vulnerability. Please do not report them.

Issues not classed as security relevant:

Vulnerability Information

You can usually find information on known vulnerabilities for an Apache project on the project's web pages. For convenience, consult the list of security information pages for Apache projects. If you can't find the information you are looking for on the project's web site, ask your question on the project's users mailing list. Do not ask the security contacts directly about:

The relevant project's users list is the place to ask such questions. The Apache Security Team and any project security team will ignore any such questions you send directly to them.

Vulnerability handling

An overview of the vulnerability handling process is:

Committers should read a more detailed description of the process. Reporters of security vulnerabilities may also find it useful.

Discussion

Committers and Security Researchers are encouraged to join our community discuss list.