Re: Vulnerability Reporting and Resolution Process for Kamailio
Daniel-Constantin Mierla via sr-users <[email protected]> Tue, 30 Jun 2026 19:00:16 +0200
| Newsgroups | gmane.comp.voip.ser |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--===============1069702147==
Content-Type: multipart/alternative;
boundary="------------B1UR7WWRYJoWBIMQjheRGSJs"
Content-Language: en-GB
This is a multi-part message in MIME format.
--------------B1UR7WWRYJoWBIMQjheRGSJs
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Hello,
Kamailio is a community-oriented open source project, there is not a big
company controlling it, but many (commercial/academic/individual)
entities collaborating to develop and maintain it.
If you look for professional/commercial support, some entities offering
such services are listed at:
- https://www.kamailio.org/w/business-directory/
You can also email to business mailing list or search on the web for
more options in this direction.
For security reporting, the current procedure is presented by:
- https://github.com/kamailio/kamailio/blob/master/SECURITY.md
Handling of the reports is done by a group of people selected from the
community, the reports may be forwarded to appropriate developers when
they are about a component not maintained by a developer in the security
group.
Cheers,
Daniel
On 30.06.26 18:49, Chandramouli P wrote:
> Dear Mr. Daniel,
>
> I hope this email finds you well.
>
> We have successfully deployed the Kamailio framework in our production
> environment, and it has been instrumental in helping us meet our
> operational requirements. We truly appreciate the robustness and
> flexibility that Kamailio offers.
>
> As part of our organization's security policies, we conduct periodic
> software scans using industry-standard tools to identify potential
> vulnerabilities across our technology stack, including Kamailio.
>
> In this regard, I would like to understand the following:
>
> 1. If we identify any vulnerabilities in the Kamailio framework during
> our scans, is there a process through which these can be reported to
> the Kamailio development team for resolution?
> 2. Would such vulnerabilities be addressed and patched by the core
> team, or is there a community-driven process we should be aware of?
> 3. If there is a defined disclosure or escalation process (e.g., a
> security mailing list, issue tracker, or responsible disclosure
> policy), could you kindly point us to the relevant resource?
>
> Understanding this process will help us align our internal compliance
> requirements with the appropriate support channels and ensure we
> follow the correct procedure when reporting any findings.
>
> Thank you for your time, and I look forward to your guidance.
>
> Best regards,
> Chandramouli.
--
Daniel-Constantin Mierla (@ asipto.com)
twitter.com/miconda -- linkedin.com/in/miconda
Kamailio Consultancy, Training and Development Services -- asipto.com
--------------B1UR7WWRYJoWBIMQjheRGSJs
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit
<!DOCTYPE html>
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p><font size="4">Hello,</font></p>
<p><font size="4">Kamailio is a community-oriented open source
project, there is not a big company controlling it, but many
(commercial/academic/individual) entities collaborating to
develop and maintain it.</font></p>
<p><font size="4">If you look for professional/commercial support,
some entities offering such services are listed at:</font></p>
<p><font size="4">- <a class="moz-txt-link-freetext" href="https://www.kamailio.org/w/business-directory/">https://www.kamailio.org/w/business-directory/</a></font></p>
<p><font size="4">You can also email to business mailing list or
search on the web for more options in this direction.</font></p>
<p><font size="4">For security reporting, the current procedure is
presented by:</font></p>
<p><font size="4">-
<a class="moz-txt-link-freetext" href="https://github.com/kamailio/kamailio/blob/master/SECURITY.md">https://github.com/kamailio/kamailio/blob/master/SECURITY.md</a></font></p>
<p><font size="4">Handling of the reports is done by a group of
people selected from the community, the reports may be forwarded
to appropriate developers when they are about a component not
maintained by a developer in the security group.</font></p>
<p><font size="4">Cheers,<br>
Daniel</font></p>
<div class="moz-cite-prefix">On 30.06.26 18:49, Chandramouli P
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:CAKYJ-7B2=Odp=hkDxw-=wos+CLBuLHhKEa0UGV0cG90jcTAbQg@mail.gmail.com">
<meta http-equiv="content-type" content="text/html; charset=UTF-8">
<div dir="ltr">
<div class="gmail_default"
style="font-family:arial,helvetica,sans-serif">Dear Mr.
Daniel,<br>
<br>
I hope this email finds you well.<br>
<br>
We have successfully deployed the Kamailio framework in our
production environment, and it has been instrumental in
helping us meet our operational requirements. We truly
appreciate the robustness and flexibility that Kamailio
offers.<br>
<br>
As part of our organization's security policies, we conduct
periodic software scans using industry-standard tools to
identify potential vulnerabilities across our technology
stack, including Kamailio.</div>
<div class="gmail_default"
style="font-family:arial,helvetica,sans-serif"><br>
</div>
<div class="gmail_default"
style="font-family:arial,helvetica,sans-serif">In this regard,
I would like to understand the following:<br>
<br>
1. If we identify any vulnerabilities in the Kamailio
framework during our scans, is there a process through which
these can be reported to the Kamailio development team for
resolution?<br>
2. Would such vulnerabilities be addressed and patched by the
core team, or is there a community-driven process we should be
aware of?<br>
3. If there is a defined disclosure or escalation process
(e.g., a security mailing list, issue tracker, or responsible
disclosure policy), could you kindly point us to the relevant
resource?<br>
<br>
Understanding this process will help us align our internal
compliance requirements with the appropriate support channels
and ensure we follow the correct procedure when reporting any
findings.<br>
<br>
Thank you for your time, and I look forward to your guidance.<br>
<br>
Best regards,<br>
Chandramouli.</div>
</div>
</blockquote>
<pre class="moz-signature" cols="72">--
Daniel-Constantin Mierla (@ asipto.com)
twitter.com/miconda -- linkedin.com/in/miconda
Kamailio Consultancy, Training and Development Services -- asipto.com</pre>
</body>
</html>
--------------B1UR7WWRYJoWBIMQjheRGSJs--
--===============1069702147==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
__________________________________________________________
Kamailio - Users Mailing List - Non Commercial Discussions -- [email protected]
To unsubscribe send an email to [email protected]
Important: keep the mailing list in the recipients, do not reply only to the sender!
--===============1069702147==--