Policies, Notices and Other Agreements
Coordinated Vulnerability Disclosure
Qt Group's policy for reporting and responding to security vulnerabilities
Qt Group is committed to the security of its products and values the work of independent researchers who help us find and fix vulnerabilities. This page explains how to report a suspected security vulnerability in a Qt Group product, what to expect once you do, and the commitments we make to researchers who disclose responsibly. This page is maintained by Qt Group's Product Security Incident Response Team (PSIRT).
Reporting Channels
Qt Group operates three reporting channels. Which channel applies depends on what is affected, not on who is reporting.
Qt Group commercial products
Vulnerabilities in Qt Group commercial products are reported to:
Reports are received and handled by the PSIRT.
Open-source Qt products (Qt Project)
Vulnerabilities in open-source Qt components governed by the Qt Project are reported to:
The Qt Project Core Security Team coordinates the response, working with the relevant maintainers. Qt Group may assign Common Vulnerabilities and Exposures (CVE) IDs for verified vulnerabilities in its scope as a CVE Numbering Authority (CNA).
Qt Group infrastructure and corporate systems
Suspected vulnerabilities in Qt Group's own IT infrastructure and corporate systems including internal servers, corporate email, HR systems, development and build infrastructure, and the non-product parts of Qt Group's public web presence are reported to:
Reports on this channel are handled by Qt Group IT Security under Qt Group's information security management system according to internal policies and procedures, rather than this policy.
What to Include in a Report
To enable prompt triage and assessment, reports should include:
- A clear description of the vulnerability and the affected product(s) and version(s)
- The type of vulnerability (e.g. memory corruption, injection, authentication bypass)
- Steps to reproduce, proof-of-concept code, or a demonstration where possible
- The potential impact — what an attacker could achieve if the vulnerability were exploited
- Whether the vulnerability is believed to be currently exploited in the wild, including any available evidence or examples
- Your preferred contact method for follow-up communication
- Whether you wish to be credited in the public advisory
Incomplete reports will be acknowledged and triaged based on the information provided. We may request additional technical details during the investigation.
Researcher Commitments (Safe Harbor)
Qt Group recognizes the essential role that security researchers play in improving the security of our products and the broader software ecosystem. In return for responsible disclosure in accordance with this policy, Qt Group makes the following commitments:
No legal action for good-faith research
Qt Group will not pursue civil or criminal legal action against researchers who discover and report vulnerabilities in good faith and in accordance with the terms of this policy. Good-faith research means accessing only systems and data necessary to demonstrate the vulnerability; avoiding actions that could harm Qt Group systems, customers, or users; not exfiltrating, modifying, or destroying data; not performing denial-of-service attacks; and coordinating disclosure with Qt Group before publishing.
Confidentiality of reports
Qt Group will treat vulnerability reports as confidential. Report contents will be shared only with personnel who need to know to investigate and remediate the issue, and with coordinating bodies such as NCSC-FI/Traficom and ENISA where required by law. Qt Group will not publicly attribute a report to a researcher without their explicit consent.
Reporter credit
Reporters who wish to be credited in the public security advisory will be acknowledged by name (or handle, as preferred) when the vulnerability is disclosed, unless the reporter requests anonymity. Qt Group will confirm the intended credit wording with the reporter before publication.
Coordinated disclosure
Qt Group is committed to coordinated disclosure. Reporters will be notified before any public disclosure of the vulnerability, and Qt Group will share the advisory draft with the reporter for factual review (technical accuracy of the vulnerability description) prior to publication.
No bounty program
Qt Group does not currently operate a monetary bug bounty program. Recognition is provided through public advisory credit as described above in Reporter credit.
Response Commitments and SLAs
The commitments and Service Level Agreements (SLAs) below apply to Channel A. Channel B follows the Qt Project's own process, as described below.
Channel A - psirt@qt.io (Qt Group commercial products)
|
Milestone |
Target |
|
Acknowledgement of report |
Within 5 business days of receipt |
|
Status updates during remediation |
Every 30 days, or upon significant change |
|
Default coordinated disclosure embargo |
90 days from verification |
|
Public advisory and CVE publication |
After 14 days of fix availability |
Channel B - security@qt-project.org (open-source Qt components)
Reports submitted to security@qt-project.org are reviewed by the Qt Project Core Security Team, who assess relevance and severity, work with the reporter to validate the vulnerability, and take appropriate measures to address it and prevent exploitation before releasing any necessary public disclosure.
The Channel A timelines above represent targets. Complex vulnerabilities affecting multiple products or requiring significant architectural changes may require extended timelines. In such cases, Qt Group will communicate the reason for the extension and an updated target date to the reporter.
Embargo and Disclosure Conditions
Default embargo
The default embargo period is 90 days from verification. During this period, Qt Group will work to develop, test, and deploy a fix, and prepare the coordinated disclosure materials. Maintaining confidentiality during this period is part of this policy.
Embargo extension
If the fix cannot be completed within 90 days, Qt Group will notify the reporter with an explanation and a revised timeline. The intended process is that extensions are granted only with reporter agreement and documented justification.
Early disclosure for active exploitation
If evidence emerges that the vulnerability is being actively exploited in the wild, Qt Group may publish a security advisory before a fix is available. Qt Group will notify the reporter before doing so except where immediate publication is required to protect users or to fulfill regulatory obligations; for example, under Article 14 of the EU Cyber Resilience Act (CRA).
Reporter-initiated early disclosure
If a reporter intends to publish information about the vulnerability before the agreed disclosure date, they are asked to notify Qt Group at least seven (7) days in advance. Qt Group will make best efforts to accelerate the fix and coordinate disclosure.
Unresponsive reporter
Coordinating the final advisory wording with the reporter is a Qt Group commitment under Coordinated disclosure above, not a legal requirement, and it does not gate publication. The 30-day window is the period Qt Group allows a reporter to respond. Where Qt Group is unable to reach a reporter within 30 days of fix availability, it reserves the right to publish the advisory without the reporter's factual review. An unresponsive reporter will not delay publication.
CVE Numbering Authority (CNA)
Qt Group has been authorized as a CVE Numbering Authority (CNA) by the CVE Program, covering all Qt Group products. As a CNA, Qt Group is responsible for:
- Assigning CVE IDs to vulnerabilities within its CNA scope upon verification
- Publishing CVE records in the National Vulnerability Database (NVD) and CVE database within the timeframes required by the CVE Program
- Maintaining the accuracy and completeness of published CVE records
- Coordinating with the CVE Program on scope boundary questions
CNA scope: All Qt Group software products with digital elements. The authoritative scope statement is registered with the CVE Program.
Reporters will be provided with the assigned CVE ID as part of the acknowledgement of a verified vulnerability. If a reporter has already reserved a CVE ID through another CNA or Computer Emergency Response Team (CERT), Qt Group will coordinate to ensure a single CVE record is published.