generated: '2026-09-05' method: searched source: >- https://github.com/celery/celery/blob/main/SECURITY.md, https://github.com/celery/celery/security/policy published: true policy_url: https://github.com/celery/celery/security/policy policy_file: https://github.com/celery/celery/blob/main/SECURITY.md channel: email to the maintainers named in SECURITY.md channel_note: >- The policy directs reporters to email two named maintainers. Their personal addresses are published in SECURITY.md but are deliberately NOT transcribed here — read them from the source file. GitHub private security advisories are not offered as an alternative in the policy text. security_txt: false security_txt_note: >- No RFC 9116 /.well-known/security.txt is served on any host (see well-known/celery-well-known.yml — 404 on docs.celeryq.dev, www.celeryq.dev; celeryq.dev does not resolve). The disclosure route is GitHub-only. bug_bounty: program: none platforms_checked: [hackerone, bugcrowd, intigriti] result: no program found supported_versions: as_published: - version: 5.4.x supported: true - version: 5.3.x supported: false - version: 5.2.x supported: false - version: 5.1.x supported: false - version: '<5.0' supported: false finding: >- The published support matrix is stale: it names 5.4.x as the only supported line while the current release is 5.6.3 (2026-03-26) and the 5.5/5.6 series have both shipped since. A reporter reading the policy cannot tell which lines will actually receive a fix. disclosure_timeline: not stated safe_harbour: not stated cve_history_url: https://github.com/celery/celery/security/advisories