Currently the v4 (stable) branch is actively receiving security fixes. Support for the v3 branch has ended as of 2026-01-01.
The v5 branch is still early in development and only receives security fixes when they are synced from the v4 branch.
| Version | Supported |
|---|---|
| 5.x.y | |
| 4.x.y | ✅ |
| 3.x.y | ❌ |
| 2.0.x | ❌ |
| 1.2.y | ❌ |
| 1.1.y | ❌ |
| 1.0.y | ❌ |
We do not consider the following to be reportable security issues:
-
Documented features such as executable includes.
-
Issues where an insecure configuration is the entire exploit. We try to make InspIRCd secure by default and document potential issues where we can but we can not control how admins configure their servers in the wild.
-
Issues with third-party modules from contrib or another repository. These should be directed to the author of the module as documented in the
ModAuthordirective.
If you have used automated tools to discover a bug then please verify the issue manually as we receive lots of false-positive reports. Please also send a concise human-written report rather than something generated by your tool as the latter tend to be inaccurate and excessively verbose.
Please do not report security vulnerabilities on GitHub. Instead, get the attention of a developer in our development IRC channel at ircs://irc.teranova.net/inspircd.dev and PM them the details. If this doesn't get a response please email Sadie at sadie@sadiepowell.dev with "InspIRCd Security" in the subject line.
We will triage your issue as soon as possible and try to release a fixed version within a week of receiving your report. If we need to publish a security advisory we will credit all humans involved in finding the issue unless requested not to.
We appreciate all reports but the InspIRCd team does not have the resources to pay bug bounties.