Security Policy

Reporting security issues

If you wish to report a possible security issue in OpenSSL please notify us by sending an e-mail to openssl-security@openssl.org.

If you have multiple issues to report, please always send a separate e-mail for each issue.

Issue triage

Notifications are received by the OpenSSL Security Response Team (SRT) designated by the OpenSSL Foundation and the OpenSSL Corporation directors. The SRT contains resources from within the OpenSSL Foundation and the OpenSSL Corporation and also members from the Committers community who decided to participate in the SRT.

We may work in private with individuals who are not part of the SRT as well as other organisations where we believe this can help with the issue investigation, resolution, or testing.

Threat Model

Certain threats are currently considered outside of the scope of the OpenSSL threat model. Accordingly, we do not consider OpenSSL secure against the following classes of attacks:

Mitigations for security issues outside of our threat scope may still be addressed, however we do not class these as OpenSSL vulnerabilities and will therefore not issue CVEs for any mitigations to address these issues.

Prior to the threat model being included in this policy, CVEs were sometimes issued for these classes of attacks. The existence of a previous CVE does not override this policy going forward.

Issue severity

We will determine the risk of each issue, taking into account our experience dealing with past issues, versions affected, common defaults, and use cases. We use the following severity categories:

Prenotification policy

Note: researchers or intermediaries who notify us of issues may have their own prenotification policy in addition to ours.

Principles

The policy above is guided by our security principles:

This policy is primarily guidance and there might be exceptions to it if they are warranted by the circumstances. For example, if a fix for a seemingly regular issue, that was already published, is later determined to fix a security issue, some parts of the process for handling security issues might be skipped for that issue.

Security release update recommendations

Our security advisories describe the affected configurations or applications. We always recommend reviewing the advisories before updating the systems running the unfixed releases.

However in general it is a good idea to update the systems as soon as possible with the security update releases that contain Critical or High severity issue fixes.

As the Moderate and Low severity issues are either unlikely to be exploitable and/or the impact of the successful exploit is limited, we recommend scheduling the updates without undue haste.

CVSS score differences

The CVSS scoring system does not properly reflect the broad usage of the OpenSSL Library and does not fully account for likelihood of a configuration being affected. For that reason we do not use the CVSS scoring system to determine the severity and the CVSS score provided by independent parties might severely differ from the severity we have assigned.