We encourage security researchers and members of the community to report vulnerabilities to us.

Are you a project maintainer coordinating a disclosure with us? See the Maintainer Process page for step-by-step guidance.

Report a Vulnerability

Use the report form. It reaches the Points of Contact directly, asks for what we need up front, and gives your report a tracked case from the start. The form requires a sign-in with GitHub or Hex.pm so we can reach you about the report.

If you would rather not sign in, or the form is unavailable, email works as a backup:

Fingerprint: 38BD 201B 397E 28F1 F3D9 3EC7 6E03 1A81 1F26 6E21

Team

  • @IngelaAndin — Ingela Andin, OTP Core Contributor — Primary PoC
  • @maennchen — Jonatan Männchen, CISO, EEF — Primary PoC
  • @voltone — Bram Verburg, Security WG Chair — Primary PoC
  • @ericmj — Eric Meadows-Jönsson, Hex.pm Core Maintainer
  • @pjullrich — Peter Ullrich, Ecosystem Security Researcher

Questions & Suggestions

For general questions, use GitHub Discussions.

Note: GitHub Discussions are public. Never report or include vulnerability details there.