Skip to content

Security: voltsparx/NetRecon

SECURITY.md

Security Policy

Scope

This repository contains a security assessment tool. Security issues in this project can impact users, scanned environments, and downstream automation.

Please report vulnerabilities responsibly and do not disclose them publicly before maintainers have time to investigate.

Supported Versions

Version Supported
4.7.x Yes
< 4.7 No

Reporting a Vulnerability

Send reports to: voltsparx@gmail.com

Please include:

  • Vulnerability title and impact summary
  • Affected file(s), module(s), and version
  • Reproduction steps
  • Proof-of-concept details (safe/non-destructive)
  • Suggested fix (if available)

Response Targets

  • Initial acknowledgment: within 72 hours
  • Triage and severity decision: within 7 days
  • Fix timeline: depends on severity and complexity

Disclosure Process

  1. Report privately by email.
  2. Maintainer validates and triages.
  3. A patch is prepared and tested.
  4. Coordinated disclosure is performed after fix availability.

Safe Harbor

Good-faith security research is welcome when performed legally and without privacy violations, service disruption, or data destruction.

Do not:

  • Access data you are not authorized to access
  • Degrade target availability
  • Run destructive payloads
  • Exfiltrate sensitive information

User Safety Notice

This tool is for authorized security testing only. Users are responsible for complying with local laws, regulations, and contractual scope.

There aren’t any published security advisories