Our team is doing there best to ensure security across our codebase. Nevertheless, mistakes happen and we are grateful for anyone reports possible vulnerabilities.
Please send any security concerns to security@digitalservice.bund.de.
- Include as much information as possible - even insignificant details may be helpful
- Add the affected release version / commit if possible
- You may use our public key to encrypt your mail
Do not report security vulnerabilities through GitHub issues, as this publicly discloses the vulnerability immediately!