Skip to content

Security: qt/qt5

Security

SECURITY.md

Security policy

Reporting a vulnerability

Report suspected security vulnerabilities in Qt by email to security@qt-project.org. Do not report them in the public bug tracker at bugreports.qt.io.

If you hold a commercial license, you can instead report the issue to the Qt Company support team through the support portal, using the "Security Issues" category.

The policy

QUIP 15 is the Qt Project Security Policy. It is the authoritative source for how the project handles security issues, and it covers:

  • How reports are received, acknowledged, and triaged, and in what time frame.
  • Who is responsible for addressing an issue, and how it is escalated.
  • How issues are disclosed, including CVE handling and notification of packagers.
  • Which versions of Qt fixes are guaranteed for.

Security announcements are published to the announce mailing list.

Qt customers with a commercial license now have the opportunity to subscribe to the Qt Early Warning List in the Customer Portal. The EWL subscription requires an active Commercial Qt license.

Related material

  • Security in Qt — what Qt does and does not protect against, and how to use Qt securely.
  • QUIP 23 — the Qt-Security header that marks how security-relevant a source file is.
  • QUIP 16 — the branch policy, which governs which branches accept which changes.
  • Coordinated Vulnerability Disclosure Policy - Terms and Conditions of Coordinated Vulnerability Disclosure Policy at Qt Group.

There aren't any published security advisories