This project is maintained by Gcore.
Gcore takes the security of our software, systems, and services seriously. This includes all source code repositories managed through our GitHub organization at https://github.com/g-core and our digital assets listed below. If you believe you have found a security vulnerability in any Gcore-owned system or repository, please report it to us as described below in accordance with our vulnerability disclosure policy.
Please do not report security vulnerabilities through public GitHub issues or other public channels. Instead, please report them to our security team via email:
- Email: bugbounty@gcore.com
Please include the following information to help us triage your report:
- Type of vulnerability (e.g., XSS, SQLi, RCE, etc.)
- Affected system/URL and version (if applicable)
- Step-by-step instructions to reproduce the issue
- Proof-of-concept code or screenshots (if available)
- Potential impact of the vulnerability
- Any additional context or configuration details
For urgent matters, please include "Urgent Security Report" in your subject line.
This policy applies to the following Gcore assets:
*.gcore.com(except explicitly excluded domains)*.gcorelabs.com*.gcore.lu*.gcore.top- GitHub repositories under g-core
The following are explicitly excluded from our bug bounty program:
- Third-party systems and services
hosting.gcore.comkvm.gcore.comdci.gcore.comsupport.gcore.com(Zendesk portal)*.gcdn.coroadmap.gcore.commeet.gcore.comand related video demo apps- Denial of Service (DoS/DDoS) vulnerabilities
- Social engineering or physical attacks
- Non-exploitative informational disclosures
- UI/UX bugs and spelling errors
We prefer all communications to be in English.
Gcore follows coordinated vulnerability disclosure practices as outlined in our:
Valid reports may qualify for rewards through our bug bounty program. Please review our full program details for eligibility requirements and reward guidelines.
Security Researchers: We appreciate your efforts to make Gcore safer. For career opportunities, visit Gcore Careers. Canonical Policy: https://gcore.com/.well-known/security.txt