Skip to content

Security: Simpler1/ZoneMinder

Security

SECURITY.md

Security Policy

Supported Versions

We do not have the resources to support every old version. ZoneMinder uses Semantic Versioning: even minor versions are stable, odd are development. We support the current stable release series and the current development series; the previous stable series receives security fixes on a best-effort basis.

Version Supported
1.39.x (dev)
1.38.x (stable)
1.36.x (legacy) ⚠️ best-effort security fixes
< 1.36.x

Reporting a Vulnerability

Please report security vulnerabilities privately so we can fix them before they are disclosed publicly. Two options:

  1. GitHub Private Vulnerability Reporting (preferred) — go to the Security tab and click Report a vulnerability. This opens a private advisory where we can collaborate on a fix and issue a CVE.
  2. Emailisaac@zoneminder.com.

Please do not open a public GitHub issue for a suspected vulnerability. Non-sensitive hardening suggestions (defense-in-depth with no exploit path) are fine as normal issues or pull requests.

We aim to acknowledge reports within a few days and to coordinate disclosure once a fix is available.

There aren't any published security advisories