generated: '2026-07-25' method: searched probe: true source: https://github.com/Netcracker/qubership-apihub/blob/main/SECURITY.md policy: - https://github.com/Netcracker/qubership-apihub/blob/main/SECURITY.md contact: - opensourcegroup@netcracker.com bug_bounty: program: false note: No HackerOne, Bugcrowd or Intigriti program was found for Netcracker. security_txt: false process: report_to: opensourcegroup@netcracker.com triage: >- "Please, report any security issue to opensourcegroup@netcracker.com where the issue will be triaged appropriately." Publicly disclosed vulnerabilities are to be emailed IMMEDIATELY so the patch, release and communication process can start. release_policy: >- A vulnerability found in the latest stable release is fixed in a patch version of that release (e.g. found in 2.5.0 -> fixed in 2.5.1). Older versions do not get security releases by default. Issues that affect no public release are fixed in main before the next version for medium/high severity; low severity may be scheduled for a future release. third_party_testing: source: https://www.netcracker.com/portfolio/services/netcracker-cybersecurity claim: >- "Independent vulnerability assessments and penetration testing of Netcracker networks by third-party organizations." evidence: - source: https://github.com/Netcracker/qubership-apihub/blob/main/SECURITY.md kind: SECURITY.md status: 200 - source: https://www.netcracker.com/.well-known/security.txt kind: security.txt status: 404 - source: https://www.netcracker.com/security kind: disclosure page status: 404 scope_note: >- The published disclosure process covers the open-source Qubership repositories. No product-security or coordinated-disclosure page exists on netcracker.com for the commercial BSS/OSS portfolio; customers report through their engagement.