generated: '2026-09-06' method: searched source: >- https://www.authelia.com/policies/security/ (last updated 2026-08-24), https://github.com/authelia/authelia/blob/master/SECURITY.md, https://github.com/authelia/authelia/security/policy and https://github.com/authelia/authelia/security/advisories. description: >- Authelia operates a written coordinated vulnerability disclosure programme with a published policy, named contact channels, and a public advisory record. There is no bug bounty and no monetary reward. The automated probe (probe-security-programs.py) reported none for this provider because Authelia serves no /.well-known/security.txt; the programme is real and is published as a policy page instead. program: exists: true type: coordinated-vulnerability-disclosure formerly: responsible disclosure policy_url: https://www.authelia.com/policies/security/ policy_last_updated: '2026-08-24' repository_policy: https://github.com/authelia/authelia/blob/master/SECURITY.md bug_bounty: false bounty_platform: null safe_harbor_stated: false contacts: - channel: github-private-vulnerability-reporting url: https://github.com/authelia/authelia/security/advisories preferred: true detail: GitHub's private vulnerability reporting, for reporters with a GitHub account. - channel: email address: security@authelia.com preferred: true detail: >- Published on the policy page in obfuscated form ("security at authelia dot com"). Accessible only to core team members and used exclusively for vulnerability disclosure. - channel: chat detail: >- Direct message to a core team member on Discord or Matrix. Explicitly discouraged in favour of the two channels above. discouraged: true requirements: - Severity ratings must use CVSSv4. - >- Any use of Generative AI in discovery, reporting, proof-of-concept or suggested fix must be fully disclosed, including how and where it was used. See https://www.authelia.com/policies/artificial-intelligence/. - Reporters must include configuration or architecture preconditions needed to trigger the vulnerability. - Do not open a public issue, notify publicly, or disclose to third parties before coordination. - Reports and interactions are subject to the Code of Conduct. advisories: url: https://github.com/authelia/authelia/security/advisories format: GitHub Security Advisories (GHSA), with CVE assignment recent: - id: GHSA-j748-h363-wqj8 published: '2026-05-26' severity: low summary: Edge case access control rule domain miss due to lack of canonicalization. - id: GHSA-hjj4-hfjm-fmrj published: '2026-05-26' severity: medium summary: Missing username canonicalization in Basic Auth when using LDAP. - id: GHSA-gmfg-3v4q-9qr4 published: '2026-03-21' severity: low practice: >- Advisories are cross-referenced from the GitHub release that fixes them, so a reader of the changelog can tie a patch release to the specific advisory it closes. remediation_window: vulnerability_fixes: >- Workarounds and patches published in the advisory; backported to the last 3 minor versions on request. See https://www.authelia.com/policies/versioning/. well_known_security_txt: served: false probed: - url: https://www.authelia.com/.well-known/security.txt status: 404 - url: https://authelia.com/.well-known/security.txt status: 404 note: >- The single most valuable improvement available to Authelia here: an RFC 9116 security.txt pointing at the existing policy page and the existing security@ address would make a real programme machine-readable at zero cost. external_audit: status: fundraising detail: >- Every page of www.authelia.com carries a "Help us fund a security audit" banner as of 2026-09-06. No completed third-party audit is published. certifications: []