The latest stable release and current development builds of Dispatcharr receive security updates. Older releases do not receive security updates. For critical issues, maintainers may backport a fix at their discretion.
Please do not report suspected vulnerabilities through public GitHub issues, discussions, or public Discord channels. Instead, use one of these reporting channels:
| Method | How-To |
|---|---|
| GitHub | Use the repository's Report a vulnerability button |
| Send a report to security@dispatcharr.tv |
Include as much of the following as possible:
- The affected Dispatcharr version or development build.
- Deployment details and relevant configuration.
- Steps to reproduce, including a minimal proof of concept when available.
- The potential impact and affected components or endpoints.
- Relevant logs, request and response details, or screenshots. Do not include passwords, API keys, tokens, stream URLs, or other secrets.
Maintainers will review the report, assess its impact, and may contact you for additional information or to validate a fix.
Public disclosure is your choice. We ask that you give maintainers a reasonable opportunity to investigate and address the issue before sharing details publicly. We will work with reporters to coordinate disclosure after a fix or mitigation is available.