Diaspora · Vulnerability Disclosure

Diaspora Vulnerability Disclosure

Vulnerability disclosure

diaspora* runs a published, coordinated vulnerability disclosure program. There is a dedicated security mailbox with a published PGP fingerprint and a stated supported-versions scope. There is no bug bounty and no commercial disclosure platform — this is a volunteer free-software project, and the process is email-based.

Diaspora runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

CompanySocialSocial NetworkingDecentralizedFederatedOpen SourcePrivacyFediverseMessagingOpenID Connect
Program: Hackerone

Disclosure Policy

Security Contact

Contact
emailsecurity@diasporafoundation.org
Contact
noteA team of developers monitors the security mailbox.
Contact
pgp_fingerprintAB0D AB02 0FC5 D398 03AB 3CE1 6F70 243F 27AD 886A
Contact
pgp_key_lookuphttps://pgp.mit.edu/pks/lookup?op=get&search=0x6F70243F27AD886A

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-20'
method: searched
source: >-
  https://github.com/diaspora/diaspora/blob/develop/SECURITY.md (fetched via raw.githubusercontent.com,
  HTTP 200) and https://github.com/diaspora/diaspora/security/policy (HTTP 200). Corroborated by
  the Security section of the 0.9.1.0 and 0.9.0.0 entries in the project Changelog, which credit
  external reporters and cite CVE identifiers.
docs: https://github.com/diaspora/diaspora/security/policy
description: >-
  diaspora* runs a published, coordinated vulnerability disclosure program. There is a dedicated
  security mailbox with a published PGP fingerprint and a stated supported-versions scope. There
  is no bug bounty and no commercial disclosure platform — this is a volunteer free-software
  project, and the process is email-based.

program:
  published: true
  type: coordinated-disclosure
  bug_bounty: false
  platform: none
  note: >-
    Not on HackerOne, Bugcrowd or Intigriti. No monetary rewards are offered.

contact:
  email: security@diasporafoundation.org
  pgp_fingerprint: AB0D AB02 0FC5 D398 03AB 3CE1 6F70 243F 27AD 886A
  pgp_key_lookup: https://pgp.mit.edu/pks/lookup?op=get&search=0x6F70243F27AD886A
  note: A team of developers monitors the security mailbox.

policy_url: https://github.com/diaspora/diaspora/security/policy
policy_file: https://github.com/diaspora/diaspora/blob/develop/SECURITY.md

scope:
  supported_versions:
  - The latest stable release
  - The current state of the develop branch
  out_of_scope:
  - Security issues in older releases
  note: >-
    Because every pod is independently operated, patch adoption is up to each podmin; the project
    scope covers the software, not any particular deployment.

security_txt:
  published: false
  note: >-
    No /.well-known/security.txt was found on diasporafoundation.org, diaspora.social or
    joindiaspora.com — see well-known/diaspora-well-known.yml. The disclosure policy is published
    as SECURITY.md in the source repository instead.

track_record:
  evidence:
  - release: 0.9.1.0
    date: '2026-04-07'
    summary: >-
      Fixed a vulnerability in the OpenID Connect API implementation where an attacker could use
      malicious client registrations to trigger HTTP requests within the pod's private network
      (SSRF via Dynamic Client Registration). Externally reported and credited in the changelog.
    relevance: Directly affects the API authentication surface documented in authentication/.
  - release: 0.9.0.0
    date: '2024-06-16'
    summary: >-
      Fixed a potential 2FA brute force attack (CVE-2024-0227), crediting Christian Reitter
      (Radically Open Security) and Chris MacNaughton (Centauri Solutions).
    cve: CVE-2024-0227

related:
  domain_security: security/diaspora-domain-security.yml
  well_known: well-known/diaspora-well-known.yml
  lifecycle: lifecycle/diaspora-lifecycle.yml