Skip to content

Security: AetherAC/Web

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Instead, please report them via email to contact@abnt.it or here.

You should receive a response within 48 hours. If for some reason you do not, please follow up via email to ensure we received your original message.

What to Include

To help us respond effectively, please include:

  • Type of vulnerability (e.g., exploit, bypass, crash, etc.)
  • Impact of the vulnerability
  • Steps to reproduce the vulnerability
  • AetherAC version affected
  • Server platform and version (Paper/Purpur/Folia/Spigot/etc.)
  • Any relevant logs or packet captures (remove sensitive information)

Disclosure Timeline

We follow a responsible disclosure process:

  1. Initial report — Vulnerability submitted via email
  2. Acknowledgment — Confirmation of receipt within 48 hours
  3. Validation — Investigation and verification of the vulnerability
  4. Fix development — Development of a fix (priority based on severity)
  5. Release — Patch released with security advisory

We aim to release fixes as quickly as possible, but timelines depend on the complexity and severity of the vulnerability.

Security Advisory

Security vulnerabilities fixed in releases will be published as GitHub Security Advisories. We will credit reporters unless they wish to remain anonymous.

Supported Versions

Version Supported
Latest stable release ✅
Previous major version ⚠️ Security patches only
Older versions ❌

No Backdoors

AetherAC contains no backdoors, hidden features, or telemetry that collects personally identifiable information.

Questions?

If you have questions about this security policy, please email contact@abnt.it.

There aren't any published security advisories