Introduction
At SUSE, we are deeply committed to maintaining the trust of our customers and the broader open-source community. Open collaboration, transparency, and secure product development are fundamental to our mission. This page serves as the official point of contact for reporting potential security vulnerabilities in SUSE products or infrastructure. Through our Coordinated Vulnerability Disclosure (CVD) process, we invite researchers and security professionals to work together with us to identify, address, and resolve security issues responsibly.
How to report a vulnerability
Please use whichever of the following channels is appropriate:
- Product vulnerabilities: psirt@suse.com
- SUSE infrastructure vulnerabilities: cybersecurity@suse.com
- Web form (accepts anonymous reports): CRA Form
We recommend OpenPGP encrypted and signed email, please check the Mail Encryption section for more details.
English is our preferred reporting language.
You may also report indirectly, and anonymously if you request it, through a CSIRT designated as national coordinator for coordinated vulnerability disclosure.
To enable SUSE to assess and address the issue in a timely manner, reports must
include the following information, where known:
- the affected product and version;
- the environment in which the issue was found;
- the steps to reproduce it;
- how an attacker could exploit it;
- and the immediate impact of exploitation.
Acknowledgement / What to expect
Should you choose to disclose a pertinent security concern and assist us in strengthening our collective security posture as an organization, we would be pleased to offer official public recognition for your contribution. Nevertheless, it is important to clarify that SUSE does not offer monetary compensation or material incentives for vulnerability reports (bug bounty program).
While every report is carefully evaluated, SUSE will not pursue further action or grant acknowledgment for submissions that fall under the following categories:
- findings that have previously been disclosed by another researcher,
- speculative vulnerabilities lacking a definitive proof of concept.
Mail Encryption
To ensure the integrity and confidentiality of our communications, we recommend that individuals reaching out to the SUSE Security team utilize PGP/GPG encryption. Note that while message contents are protected, the email subject or the names of any attached files will be excluded from encryption.
Our official public key is available here:
pub ed25519/0xE0D1EF75DEBDFEE9 2026-09-01 [SC] [expires: 2037-09-01]
Key fingerprint = AB20 5CE3 088C 1F1B CE74 DC99 E0D1 EF75 DEBD FEE9
uid [ full ] SUSE Product Security Incident Response Team psirt@suse.com
sub cv25519/0xA4B7B686CC4152BD 2026-09-01 [E] [expires: 2037-09-01]
Key fingerprint = B13E 46DE 87EB 81D5 15E1 1909 A4B7 B686 CC41 52BD
The key is listed below in ASCII encoded form.
-----BEGIN PGP PUBLIC KEY BLOCK-----
mDMEapZ8VhYJKwYBBAHaRw8BAQdADoggNgBrXHimYH+7t5WVzBnhQmT8UPUIQQWH
pzLMaB+0PVNVU0UgUHJvZHVjdCBTZWN1cml0eSBJbmNpZGVudCBSZXNwb25zZSBU
ZWFtIDxwc2lydEBzdXNlLmNvbT6ImQQTFgoAQRYhBKsgXOMIjB8bznTcmeDR73Xe
vf7pBQJqlnxWAhsDBQkUsUK6BQsJCAcCAiICBhUKCQgLAgQWAgMBAh4HAheAAAoJ
EODR73Xevf7pRkMA/0XDeysUhC66NgiF7AVno+QBkyJso2pkbQQG3su+Oi9hAQCd
yy3iScttdmFKTqQr4N7redFAJ3Esw5vtxVzMHZhpCIkCMwQQAQgAHRYhBFzzxI6z
KP0xgVwUfZLb1rIpR3voBQJqlnyMAAoJEJLb1rIpR3voRUUP/0rHbb/m47zHc834
G1CPaExiYOrtdckXNDwjno/r+2RppWy6ZxtM8KeLz+414NPxYUPNlyAvXd9pY3lW
sxQkDyJFrIJd0MDXiM8gDPyMuEB9k+yWeofJLcx6LfLvwJnFLwSSHcUWqmPcC6AI
TYVRhY6Gn9sNfJ5DnjQCxahZN55aGff2v0KiSPHrDqE59soLOQH7Vv2xuFVoWIYG
E8FZlzfIsfXJX0mBMrDxXO1+SGzDEdmcgLihhLHCcgmTCizz9S2qGLw3yaeI3NDB
xWafFrW80XGELXn+DdWP/khuU+PGfb0JcfroyR6GGNfAX5BC9O7yePGya+fZB8UD
puf93Q58Exu23KmQ00d0p2ey5t+KSFzmhk4knh6T50qEPm5Z04dwlzbnGwrn9qKS
iZuHn82Xx5B8eQ0nUN9jql1k/tjmeSXrhzfwoGhp4vCbz0AwAAglNo7pEb7j0xHF
C866ZCrQsQxVUcJCSox0HC27YZUvw2fvc57Lb+tkIxGi/AS0/Pe6lRHannqDzpwV
EW4WWIf6wE746M38q779p6PrH8Cu+aVWVCw+ZFNgv7GB/k0NeQUeliZ/xb40wKo4
zwm6X8emOI/jkQ6fF9JCw7PXf+eFsy1CbB8sKCkFDkew1g9008lWnywxtx79c+Ks
tTMW5IlYQE5wWvLmPG87Sow9wHUSiQIzBBABCAAdFiEEXPPEjrMo/TGBXBR9ktvW
silHe+gFAmqWfLMACgkQktvWsilHe+h1Eg//bHdyPYiJPkKvsHf1guYD/OwEWm32
1KlfKBKzpM1lZyyHjmNLetnytmypixiRvLuk1R4bTrn+AzwfvaJxqP1O3Ffm6Nub
npjhasBK1ehHL1KbN3ayiuOjjHEubj4ODtZd7QTjSLPNCgapL/N69lHoE6z7Hn+O
MSdy+tZdNKYmQSZdtxsLdzUsnbBItQS2X9Ow1Mwxnj2VHlmJ2WAz+RYh/npFbxc0
jBDuGg8BIAQRovOym7zP3ubIMlWEbj0uEyNdoFh7qyBp/dC7cqMVykMJHMS2ywNJ
ic20wHZNioRkvRmBIfUS2LSSoSX75y5NWunm9umLZq9bveCCANtRnWA/OrWjM9Dv
bYgn3MUP50ppD8VhWg36jqWjQ4el4J+pZR+NnaqQb5EfFqk6LfHgcbEyBjvwx9EI
AxBTLUEsMCQh65O1tA8flp7EsnPNS5Gq43ceZ/2zqSN+nT6P9USrlvoaY7DycG3H
pW0ivUcILFem3Dv+hpOiu8l4fG34Sc+5iSsMP+3C4FF3b3zaT/OZVcrYz+9Lbel+
wnttWiXAc1uY6g0BDBWfxqINMHTuqyI28kJpJwohIsAJupWiLBPJirbHxz3sCH1k
iTwKsQ9AQB6QG5kbTyI2XvMAoRS9sLJOIgj1XCQ5iPCnCqCW/5yUZXTLEE1hgDrP
4vNXGiDotSsrg1a4OARqlnxWEgorBgEEAZdVAQUBAQdAIK9oQ08e7coYwqNlcumv
kbxAtYZp/znHfF18qmaClEgDAQgHiH4EGBYKACYWIQSrIFzjCIwfG8503Jng0e91
3r3+6QUCapZ8VgIbDAUJFLFCugAKCRDg0e913r3+6UnaAQCo9GLby0CgazcDlo91
X99FhvSAKWmszQg/HXmFACe0IwD/Sv7t62yxGgGebbWdzfPbJOMdqo5ZPq8Yqzal
CNPwEwU=
=qfoM
-----END PGP PUBLIC KEY BLOCK-----
Coordinated Vulnerability Disclosure Policy (CVD)
SUSE values open collaboration and trust which is why we've designed our Coordinated Vulnerability Disclosure ("CVD") program to encourage contributions in mitigating security vulnerabilities.
We work closely with vendors, researchers, partners, and community coordinators to address newly identified security vulnerabilities.
To learn more about how SUSE manage security issues, please refer to the SUSE Coordinated Vulnerability Disclosure Policy.