Re: Vulnerability Reporting and Resolution Process for Kamailio
Chandramouli P via sr-users <[email protected]> Wed, 1 Jul 2026 01:08:31 +0530
| Newsgroups | gmane.comp.voip.ser |
|---|---|
| Message-ID | <CAKYJ-7CHt_UUxXOSYK3Vm8ipq-U7GxJbPdi_FSayCMk_jd3uew@mail.gmail.com> |
--===============1261883574== Content-Type: multipart/alternative; boundary="000000000000f658cc06557db8d6" --000000000000f658cc06557db8d6 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Dear Mr. Daniel and Mr. Fred, Thank you both for your prompt and informative responses. I appreciate Daniel's detailed explanation of Kamailio's community-oriented structure and the collaborative nature of the project. It is great to know that the framework is backed by a strong and active community of commercial, academic, and individual contributors. I have reviewed the security reporting procedure shared by Daniel: - https://github.com/kamailio/kamailio/blob/master/SECURITY.md As well as the security policy referenced by Fred: - https://github.com/kamailio/kamailio/security Both resources are very comprehensive and address our queries clearly. We now have a well-defined process to follow in the event that our internal software scans identify any vulnerabilities in the Kamailio framework. We will ensure that our team adheres to the responsible disclosure process as outlined, and we will route any findings through the appropriate channels. Thank you once again for your time and support. We look forward to continued collaboration with the Kamailio community. Best regards, Chandramouli. On Tue, Jun 30, 2026 at 10:30=E2=80=AFPM Daniel-Constantin Mierla <miconda@= gmail.com> wrote: > Hello, > > Kamailio is a community-oriented open source project, there is not a big > company controlling it, but many (commercial/academic/individual) entitie= s > collaborating to develop and maintain it. > > If you look for professional/commercial support, some entities offering > such services are listed at: > > - https://www.kamailio.org/w/business-directory/ > > You can also email to business mailing list or search on the web for more > options in this direction. > > For security reporting, the current procedure is presented by: > > - https://github.com/kamailio/kamailio/blob/master/SECURITY.md > > Handling of the reports is done by a group of people selected from the > community, the reports may be forwarded to appropriate developers when th= ey > are about a component not maintained by a developer in the security group= . > > Cheers, > Daniel > On 30.06.26 18:49, Chandramouli P wrote: > > Dear Mr. Daniel, > > I hope this email finds you well. > > We have successfully deployed the Kamailio framework in our production > environment, and it has been instrumental in helping us meet our > operational requirements. We truly appreciate the robustness and > flexibility that Kamailio offers. > > As part of our organization's security policies, we conduct periodic > software scans using industry-standard tools to identify potential > vulnerabilities across our technology stack, including Kamailio. > > In this regard, I would like to understand the following: > > 1. If we identify any vulnerabilities in the Kamailio framework during ou= r > scans, is there a process through which these can be reported to the > Kamailio development team for resolution? > 2. Would such vulnerabilities be addressed and patched by the core team, > or is there a community-driven process we should be aware of? > 3. If there is a defined disclosure or escalation process (e.g., a > security mailing list, issue tracker, or responsible disclosure policy), > could you kindly point us to the relevant resource? > > Understanding this process will help us align our internal compliance > requirements with the appropriate support channels and ensure we follow t= he > correct procedure when reporting any findings. > > Thank you for your time, and I look forward to your guidance. > > Best regards, > Chandramouli. > > -- > Daniel-Constantin Mierla (@ asipto.com)twitter.com/miconda -- linkedin.co= m/in/miconda > Kamailio Consultancy, Training and Development Services -- asipto.com > > --000000000000f658cc06557db8d6 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><div class=3D"gmail_default" style=3D"fon= t-family:arial,helvetica,sans-serif">Dear Mr. Daniel and Mr. Fred,<br><br>T= hank you both for your prompt and informative responses.<br><br>I appreciat= e Daniel's detailed explanation of Kamailio's community-oriented st= ructure and the collaborative nature of the project. It is great to know th= at the framework is backed by a strong and active community of commercial, = academic, and individual contributors.<br><br>I have reviewed the security = reporting procedure shared by Daniel:<br>- <a href=3D"https://github.com/ka= mailio/kamailio/blob/master/SECURITY.md" target=3D"_blank">https://github.c= om/kamailio/kamailio/blob/master/SECURITY.md</a><br><br>As well as the secu= rity policy referenced by Fred:<br>- <a href=3D"https://github.com/kamailio= /kamailio/security" target=3D"_blank">https://github.com/kamailio/kamailio/= security</a><br><br>Both resources are very comprehensive and address our q= ueries clearly. We now have a well-defined process to follow in the event t= hat our internal software scans identify any vulnerabilities in the Kamaili= o framework.<br><br>We will ensure that our team adheres to the responsible= disclosure process as outlined, and we will route any findings through the= appropriate channels.<br><br>Thank you once again for your time and suppor= t. We look forward to continued collaboration with the Kamailio community.<= br><br>Best regards,<br>Chandramouli.<br></div><div class=3D"gmail_default"= style=3D"font-family:arial,helvetica,sans-serif"><br></div></div><br><div = class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Tue, Jun 30,= 2026 at 10:30=E2=80=AFPM Daniel-Constantin Mierla <<a href=3D"mailto:mi= [email protected]" target=3D"_blank">[email protected]</a>> wrote:<br></di= v><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;borde= r-left:1px solid rgb(204,204,204);padding-left:1ex"><u></u> =20 =20 =20 <div> <p><font size=3D"4">Hello,</font></p> <p><font size=3D"4">Kamailio is a community-oriented open source project, there is not a big company controlling it, but many (commercial/academic/individual) entities collaborating to develop and maintain it.</font></p> <p><font size=3D"4">If you look for professional/commercial support, some entities offering such services are listed at:</font></p> <p><font size=3D"4">- <a href=3D"https://www.kamailio.org/w/business-di= rectory/" target=3D"_blank">https://www.kamailio.org/w/business-directory/<= /a></font></p> <p><font size=3D"4">You can also email to business mailing list or search on the web for more options in this direction.</font></p> <p><font size=3D"4">For security reporting, the current procedure is presented by:</font></p> <p><font size=3D"4">- <a href=3D"https://github.com/kamailio/kamailio/blob/master/SECURIT= Y.md" target=3D"_blank">https://github.com/kamailio/kamailio/blob/master/SE= CURITY.md</a></font></p> <p><font size=3D"4">Handling of the reports is done by a group of people selected from the community, the reports may be forwarded to appropriate developers when they are about a component not maintained by a developer in the security group.</font></p> <p><font size=3D"4">Cheers,<br> Daniel</font></p> <div>On 30.06.26 18:49, Chandramouli P wrote:<br> </div> <blockquote type=3D"cite"> =20 <div dir=3D"ltr"> <div style=3D"font-family:arial,helvetica,sans-serif">Dear Mr. Daniel,<br> <br> I hope this email finds you well.<br> <br> We have successfully deployed the Kamailio framework in our production environment, and it has been instrumental in helping us meet our operational requirements. We truly appreciate the robustness and flexibility that Kamailio offers.<br> <br> As part of our organization's security policies, we conduct periodic software scans using industry-standard tools to identify potential vulnerabilities across our technology stack, including Kamailio.</div> <div style=3D"font-family:arial,helvetica,sans-serif"><br> </div> <div style=3D"font-family:arial,helvetica,sans-serif">In this regar= d, I would like to understand the following:<br> <br> 1. If we identify any vulnerabilities in the Kamailio framework during our scans, is there a process through which these can be reported to the Kamailio development team for resolution?<br> 2. Would such vulnerabilities be addressed and patched by the core team, or is there a community-driven process we should be aware of?<br> 3. If there is a defined disclosure or escalation process (e.g., a security mailing list, issue tracker, or responsible disclosure policy), could you kindly point us to the relevant resource?<br> <br> Understanding this process will help us align our internal compliance requirements with the appropriate support channels and ensure we follow the correct procedure when reporting any findings.<br> <br> Thank you for your time, and I look forward to your guidance.<br> <br> Best regards,<br> Chandramouli.</div> </div> </blockquote> <pre cols=3D"72">--=20 Daniel-Constantin Mierla (@ <a href=3D"http://asipto.com" target=3D"_blank"= >asipto.com</a>) <a href=3D"http://twitter.com/miconda" target=3D"_blank">twitter.com/micond= a</a> -- <a href=3D"http://linkedin.com/in/miconda" target=3D"_blank">linke= din.com/in/miconda</a> Kamailio Consultancy, Training and Development Services -- <a href=3D"http:= //asipto.com" target=3D"_blank">asipto.com</a></pre> </div> </blockquote></div> </div> --000000000000f658cc06557db8d6-- --===============1261883574== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline __________________________________________________________ Kamailio - Users Mailing List - Non Commercial Discussions -- [email protected] To unsubscribe send an email to [email protected] Important: keep the mailing list in the recipients, do not reply only to the sender! --===============1261883574==--