This page is synced automatically from the MariaDB/governance repository and may be periodically updated.

Security policy

MariaDB Foundation is committed to ensuring all security bugs are fixed within stable MariaDB Server versions. Security issues can be reported via security@mariadb.org or under the HackerOne Program.

The MariaDB Server developers classify all security bugs according to their threat level. The threat level can be one of:

  • Critical: an exploitable vulnerability that causes arbitrary code execution or allows an
    unauthenticated user to crash the server or get access to the data.
  • Medium: everything else.

We strive to fix any Critical security bug immediately and release fixed MariaDB binaries for all supported MariaDB versions as soon as possible, usually within two weeks.

We will fix Medium security bugs as soon as possible, but we will not change our planned release schedule to get the fix out earlier.

Please review our Security Policy and Assets covered within that we have available on our HackerOne profile.

We will follow responsible disclosure procedures and will alert related projects and forks such as Oracle MySQL and Percona Server if we believe a reported security issue affects those projects as well.