If you have found a security vulnerability in tinc, please email guus@tinc-vpn.org directly. You can encrypt the email using PGP if desired. We will try to respond within 48 hours. If there is no response, try to contact us via alternate means listed at https://www.tinc-vpn.org/contact/.
We greatly prefer to use the responsible disclosure model. After we have been contacted about a potential vulnerability, we will do the following:
Currently we support the 1.0.x and 1.1.x branches of tinc.
Version | Supported |
---|---|
1.1.x | yes |
1.0.x | yes |