Report vulnerabilities privately through GitHub Security Advisories. Do not open a public issue containing secrets, credentials or an exploit.
Only main and the latest published release receive security fixes.
- affected WaveFlow Server version and operating system;
- deployment shape and reverse proxy, if any;
- affected endpoint, CLI command or SQLite operation;
- minimal reproduction and expected impact;
- whether the instance key, database, audio root or a user credential is exposed.
- local Argon2id login and rotating opaque sessions;
- the SQLite database, migration runner and global writer coordinator;
instance.keyand encrypted per-user Subsonic credentials;- library membership and future catalogue/media authorization;
- URL/query redaction in request traces;
- canonical filesystem and symlink guards as scanner/streaming land.
Cosmetic issues, generic scanner output without an exploit, administrator-triggered resource exhaustion on the administrator's own host and vulnerabilities in unmodified third-party software are normally out of scope.
WaveFlow does not currently offer a monetary bug bounty. Valid reporters may be credited in release notes after a coordinated fix.