If you think you have discovered a security issue in Teku, please report it privately using one of the methods below.
To report a security bug, email a description of the flaw and any related information (e.g. reproduction steps, version) to teku-security-report@consensys.com.
Alternatively, open this repository's Security tab and select Report a vulnerability to use GitHub private vulnerability reporting.
Do not report security issues through public issues, pull requests, or discussions.
- The version, tag, or commit you tested.
- A description of the issue and its potential impact.
- Steps to reproduce, or a proof of concept.
- How we can reach you, and whether and how you would like to be credited.
We acknowledge every report, keep you informed during triage and remediation, and agree on a disclosure timeline with you. Please allow us reasonable time to investigate and release a fix before any public disclosure. We credit reporters who wish to be named.
Consensys will not pursue or support legal action against researchers who act in good faith and in accordance with this policy. Acting in good faith means that you:
- Only access, modify, or store data that is your own or that you have explicit permission to test with.
- Avoid privacy violations, data destruction, and degradation or disruption of services.
- Do not use social engineering, phishing, or physical attacks.
- Stop testing and report immediately if you encounter personal or otherwise sensitive data.
- Report vulnerabilities in third-party dependencies to their maintainers.
- This policy does not by itself establish a bug bounty program.
- For support questions and bugs without a security impact, you can submit an issue or message us on Discord.