Skip to content

Security: WhiteDNS/WhiteVPN-Desktop

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are applied to the latest published WhiteVPN Desktop release and the default branch. Older releases may not receive backports.

Reporting a vulnerability

Use GitHub's private vulnerability reporting feature on this repository. If that feature is unavailable, contact a repository owner privately. Do not open a public issue for an unpatched vulnerability and do not include user credentials, subscription contents, or other personal data in a report.

Include the affected version and operating system, reproduction steps, impact, and any suggested remediation. Maintainers will acknowledge the report, validate it, and coordinate disclosure after a fix is available.

Security-sensitive behavior

Reports about traffic escaping the tunnel, DNS or proxy listeners exposed beyond localhost, unsafe subscription handling, privilege boundaries, update or packaging integrity, and secret exposure are in scope.

There aren't any published security advisories