Important
Found a vulnerability? Please email security@ripplemail.de — do not open a public issue.
We take the security of our project seriously and appreciate your efforts to responsibly disclose vulnerabilities.
If you discover a security vulnerability, please help us keep users safe by following these steps:
- Do not open a public issue.
- Email us at security@ripplemail.de with:
- A description of the vulnerability
- Steps to reproduce (proof of concept, if possible).
- Potential impact
- We will respond within 72 hours.
- We will provide updates as we work to resolve the issue and may request additional information.
Please report things that could put users, data, or systems at risk. Examples include (but aren't limited to):
- Account takeover or authentication bypass
- Access to another user's email or data
- Remote code execution (e.g., XSS, RCE)
- Leaking sensitive information (emails, passwords, tokens, etc.)
- Breaking encryption or transport security (e.g., TLS issues)
You don't need to report:
- Typos, styling issues, or UX bugs
- Denial-of-service (DoS) or spam/flooding
- Social engineering attacks
- Vulnerabilities in third-party dependencies we don't control (though letting us know about them is appreciated if they impact us)
In scope:
- Our official code and services under
*.ripplemail.de - The Ripple Mail clients and APIs
Out of scope:
- DoS/spam/flooding attacks
- Social engineering
- Stuff outside Ripple Mail's control
- Please give us up to 90 days to fix the issue before public disclosure.
- If you'd like credit, we'll happily mention you in our release notes/acknowledgements.
- Malicious or exploitative use of vulnerabilities is not permitted.
- We don't have a bug bounty programme, but we'll give you props for helping.
As long as you're acting in good faith:
- You won't get in trouble with us for responsibly reporting an issue.
- Please try not to mess with user data, break services, or cause downtime while testing.
Thank you for helping us keep our project and community safe! 💜