SNOMED International takes the security of our software seriously. We appreciate the efforts of security researchers and the wider community in helping us keep our tools safe for the members and users who rely on them.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, please use GitHub's private vulnerability reporting feature for this repository:
- Go to the Security tab of this repository.
- Click Report a vulnerability.
- Fill in as much detail as you can — affected version(s), steps to reproduce, potential impact, and any proof-of-concept code.
This creates a private advisory visible only to us and you, so the issue can be discussed and fixed before it's public.
(Don't see a Security tab or the report option? Email us instead — see Alternative contact below.)
| Stage | Timing |
|---|---|
| Acknowledgement of your report | Within 2 business days |
| Initial severity assessment | Within 5 business days |
| Status updates | At least every 2 weeks until resolved |
| Public disclosure / CVE | After a fix is released, typically 14–30 days later |
Response and fix timelines depend on severity — critical issues are prioritised well ahead of this schedule.
SNOMED International is a non-profit organisation, and we do not operate a paid bug bounty program. We're not able to offer financial rewards for vulnerability reports.
What we can offer is credit: with your permission, we will publicly acknowledge your contribution in the security advisory, release notes, and/or a project acknowledgements page. Let us know in your report whether you'd like to be named, remain anonymous, or use a specific handle/affiliation.
This policy covers vulnerabilities in code maintained in this repository. Vulnerabilities in third-party dependencies should ideally be reported upstream to the relevant project directly, but we're happy to be a relay if you're unsure where to send it — please still use private reporting rather than a public issue.
If you're unable to use GitHub's private vulnerability reporting, you can reach us at security@snomed.org.
We ask that you give us a reasonable opportunity to investigate and address a vulnerability before any public disclosure. We commit to working with you in good faith on a disclosure timeline once a fix is available.
Thank you for helping keep SNOMED International's software secure.