Security Contact

The FreeRADIUS security contact is security@freeradius.org. All security related information or notifications should be sent to that address. Security notifications may be signed with the pgp key aland@freeradius.org

Security of the RADIUS Protocol

The security papers page lists some general issues with RADIUS security.

Vulnerability Notifications

Non-Vulnerability Notifications

Some "vulnerability" notifications issued for FreeRADIUS are, in fact, non-issues. These notifications are usually sent by the originator to various security lists, without first notifying us. This practice is problematic, because it does not give us the opportunity to respond, or to correct the underlying problem before it can be exploited.

We therefore recommend that anyone finding a potential issue with FreeRADIUS contact us using the security contact information listed above. We will work with you to issue a coordinated statement about the problem.

People who do not contact us, and who issue "vulnerabilities" that are not real vulnerabilities get listed below. This affords us the opportunity to give an official response in a public forum.