Skip to content

Report a Vulnerability

Please let us know if you have found a security vulnerability in our software or web services.

We respect responsible disclosure. We would appreciate if a reporter does not disclose information about a vulnerability until a fix is released or within 120 days since the reporting time.

A vulnerability report can be submitted anonymously. But if you expect a reply from us, please provide your contact information below. We recommend you to use encryption for the submitted data and files. The link to our PGP key can be found below.

Privacy Policy  |  Vulnerability Disclosure Policy  |  PGP key Download

0 / 5000

Drag and drop a file here or click to upload

Allowed types: ZIP, X-ZIP-COMPRESSED

ZIP file up to 5 MB only. The attachment is packed into a password-protected archive for secure transfer.

* This field is mandatory.

Frequently asked questions

Will G DATA contact me after I report a vulnerability?

G DATA may contact a reporter for additional information or files if a vulnerability can't be reproduced in-house. However, for anonymous reports that will not be possible. 

Reporters of confirmed vulnerabilities will receive a gift of appreciation from G DATA, however no monetary rewards are possible at this point. More information is available in our Vulnerability Disclosure Policy.

Can I submit my report anonymously?

Communication between G DATA and vulnerability reporters is important, however each report can be submitted anonymously, without specifying your contact information. 

G DATA will not track any reporter and there will be no legal action for reporting vulnerabilities in our products or services.

Please note that anonymous reports can be only processed to a limited extent due to missing contact options to request additional technical details. In addition, if no contact information is provided, G DATA will not be able to acknowledge received reports and will not be able send gifts of appreciation for confirmed vulnerabilities.

Does my report need to be encrypted?

Encryption is not required, but highly recommended for vulnerability reporting. You can download our PGP key here and encrypt your ZIP archive containing the proof-of-concept and other relevant files.

If you would also like to encrypt your vulnerability report, please put it as a text file into the same ZIP archive and encrypt the archive with our PGP key.

To encrypt your submission you can use any freely-available software that allows PGP encryption, for example OpenPGP.

Can I also report security vulnerabilities via email?

You can also send a vulnerability report via e-mail to the security@gdata.de. Use a burner address if you wish to stay anonymous.

How long does it take for G DATA to respond?

Response times for received vulnerability reports and mitigation solution creation times can be found in our Vulnerability Disclosure Policy.