Our Security Policy

Reporting a vulnerability

To report a vulnerability you can either email security /at/ spamassassin.apache.org or open a Bugzilla issue being very careful to set the Component to Security so that it is not generally visible. If you create the bug report you will have access to it, as will the security team.

Security team process

The Apache process for vulnerability handling by committers is listed at Vulnerability Handling, which should be read before or along with reading the rest of this page. This writeup is our compatible version, step numbers referring to those in that document.

Once a potential vulnerability is reported to the SpamAssassin committers, the process has satisfied steps 1, 2, and 3.

Additional guidance may be required. See http://www.apache.org/security/ for more information.