Owncast appreciates good-faith efforts to improve the security of the project.
The latest stable Owncast release is the supported version. Reports that affect the current develop branch are also welcome. Previous releases are not supported, so Owncast operators should stay up to date.
- Security vulnerabilities in the latest stable Owncast release or the current
developbranch. - The Owncast server, viewer and admin interfaces, bundled APIs, chat, federation, authentication, and streaming features.
- Vulnerabilities in third-party dependencies that can be exploited through Owncast.
- Owncast-operated services under
owncast.onlinewhen tested without disrupting the service or accessing other people's data.
- Independently operated Owncast instances and the content they stream. Contact that server's operator instead.
- Issues that only affect an outdated Owncast version and are already fixed in the latest release.
- Expected actions available to an authorized server administrator that do not cross a security boundary.
- Self-XSS, best-practice suggestions, or automated scanner output without a reproducible security impact.
- Vulnerabilities in third-party software that cannot be exploited through Owncast.
- Social engineering, phishing, physical attacks, denial-of-service testing, and high-volume automated scanning.
Report suspected security vulnerabilities privately to security@owncast.online. Do not open a public GitHub issue or discussion.
Include the affected Owncast version or commit, steps to reproduce the issue, its potential impact, and any proof of concept that helps explain the report.
Please allow time for the issue to be investigated and fixed before sharing it publicly. Reports made in good faith and within the published scope are welcome.
With the reporter's permission, Owncast credits valid reports after a fix is available. Credit can include the reporter's chosen name and one link. Reporters may remain anonymous.
Owncast handles new reports by email and does not publish new GitHub Security Advisories as part of this process. CVEs may be requested when the severity and impact warrant one, at the project's discretion.