Security Policy

Supported versions

Security fixes target the latest 2.0.x release. The 3.x line will be supported after its first release. Upgrade to the latest supported release before reporting an issue as unresolved.

Reporting a vulnerability

Use GitHub private vulnerability reporting or email maxbronnikov10 bronnikovmr@gmail.com. Please include the affected version, PostgreSQL major version, a concise impact description, and a minimal reproducer when possible. Do not include production secrets or customer data.

Scope and response

Reports are in scope when they expose or corrupt data, bypass authorization, compromise server availability, or enable code execution through the RESP listener, SQL functions, shared memory, or installation and upgrade tooling.

Reports involving RESP TLS or mTLS are also in scope, including certificate-validation bypasses, unexpected plaintext access, or private-key permission checks that fail open. RESP TLS uses settings separate from PostgreSQL ssl_* settings. For non-loopback listeners, prefer TLS; enable pg_local_cache.allow_plaintext_network only for plaintext on a trusted network.

The RESP parser runs continuously under ClusterFuzzLite with AddressSanitizer and UndefinedBehaviorSanitizer on pull requests. PostgreSQL integration CI also runs a concurrent stale-read stress test with committed and rolled-back writes, cache invalidation, kill-switch changes, malformed RESP input, and plaintext and TLS listeners.

We aim to acknowledge reports within 3 business days and provide an initial triage within 10 business days. Confirmed active exploitation receives priority. Response times are targets, not a service-level guarantee.

Disclosure

We coordinate disclosure with the reporter and publish a fix and advisory together when practical. We aim for a 90-day disclosure window from confirmation; we may agree on a different date when exploitation risk, release readiness, or reporter needs warrant it. Please allow maintainers time to investigate and prepare a fix before publishing technical details.