JIRCD is currently pre-implementation (see README.md — specification and planning are complete, but no release has shipped yet). Once releases begin, supported versions will be listed here.
| Version | Supported |
|---|---|
| N/A (pre-release) | — |
Please do not report security vulnerabilities through public GitHub issues.
If you believe you've found a security vulnerability in JIRCD, report it privately using one of these channels:
- GitHub Security Advisories (preferred) — lets you disclose privately and coordinate a fix.
- Email contact@jircd.org with details.
Please include as much of the following as you can:
- A description of the vulnerability and its potential impact
- Steps to reproduce, or a proof-of-concept
- The affected version/commit, if known
You should expect an acknowledgment within a few days. This is a volunteer-maintained project, so response and fix timelines aren't guaranteed, but security reports are prioritized over other work.
Given the project's nature (an IRC server accepting untrusted network input), reports involving the following are especially relevant:
- Protocol parsing issues (malformed input causing crashes, memory exhaustion, or unexpected behavior)
- Authentication/authorization bypass (once authentication is
implemented — see
spec.md's deferred Story 3) - Administrator-privilege escalation (the in-band
OPER/EXTENSIONcommands, once implemented) - Denial-of-service vectors beyond what the documented rate-limiting is designed to handle