Skip to main content

Security

Report suspected security issues privately to security@owncast.online. Do not open a public GitHub issue.

What to include

Include the affected Owncast version, steps to reproduce the issue, its potential impact, and any proof of concept that helps explain the report. Test only systems you own or have permission to test. Do not access other people's data or disrupt a service.

Please allow time for the issue to be investigated and fixed before sharing it publicly. Reports made in good faith and within this scope are welcome.

In scope

  • Security vulnerabilities in the latest stable Owncast release or the current develop branch.
  • The Owncast server, viewer and admin interfaces, bundled APIs, chat, federation, authentication, and streaming features.
  • Vulnerabilities in third-party dependencies that can be exploited through Owncast.
  • Owncast-operated services under owncast.online when tested without disrupting the service or accessing other people's data.

Out of scope

  • Independently operated Owncast instances and the content they stream. Contact that server's operator instead.
  • Issues that only affect an outdated Owncast version and are already fixed in the latest release.
  • Expected actions available to an authorized server administrator that do not cross a security boundary.
  • Self-XSS, best-practice suggestions, or automated scanner output without a reproducible security impact.
  • Vulnerabilities in third-party software that cannot be exploited through Owncast.
  • Social engineering, phishing, physical attacks, denial-of-service testing, or high-volume automated scanning.

How reports are handled

Owncast handles new reports by email and does not publish new GitHub Security Advisories as part of this process. CVEs may be requested when the severity and impact warrant one, at the project's discretion.

Valid reports are credited on the Credits tab with the reporter's permission.

Finding this policy

Owncast publishes its reporting channel in a security.txt file following RFC 9116, so vulnerability disclosure tools such as lookup.disclose.io can route researchers to the right contact automatically.