Skip to main content
  1. Qt.io
  2. terms conditions
  3. disclosure policy

Coordinated Vulnerability Disclosure

Qt Group's policy for reporting and responding to security vulnerabilities

Qt Group is committed to the security of its products and values the work of independent researchers who help us find and fix vulnerabilities. This page explains how to report a suspected security vulnerability in a Qt Group product, what to expect once you do, and the commitments we make to researchers who disclose responsibly. This page is maintained by Qt Group's Product Security Incident Response Team (PSIRT). 

Reporting Channels 

Qt Group operates three reporting channels. Which channel applies depends on what is affected, not on who is reporting. 

Qt Group commercial products 

Vulnerabilities in Qt Group commercial products are reported to: 

psirt@qt.io

Reports are received and handled by the PSIRT. 

Open-source Qt products (Qt Project) 

Vulnerabilities in open-source Qt components governed by the Qt Project are reported to: 

security@qt-project.org

The Qt Project Core Security Team coordinates the response, working with the relevant maintainers. Qt Group may assign Common Vulnerabilities and Exposures (CVE) IDs for verified vulnerabilities in its scope as a CVE Numbering Authority (CNA). 

Qt Group infrastructure and corporate systems 

Suspected vulnerabilities in Qt Group's own IT infrastructure and corporate systems including internal servers, corporate email, HR systems, development and build infrastructure, and the non-product parts of Qt Group's public web presence are reported to: 

security@qt.io

Reports on this channel are handled by Qt Group IT Security under Qt Group's information security management system according to internal policies and procedures, rather than this policy. 

What to Include in a Report

To enable prompt triage and assessment, reports should include: 

  • A clear description of the vulnerability and the affected product(s) and version(s) 
  • The type of vulnerability (e.g. memory corruption, injection, authentication bypass) 
  • Steps to reproduce, proof-of-concept code, or a demonstration where possible 
  • The potential impact — what an attacker could achieve if the vulnerability were exploited 
  • Whether the vulnerability is believed to be currently exploited in the wild, including any available evidence or examples 
  • Your preferred contact method for follow-up communication 
  • Whether you wish to be credited in the public advisory 

Incomplete reports will be acknowledged and triaged based on the information provided. We may request additional technical details during the investigation. 

Researcher Commitments (Safe Harbor) 

Qt Group recognizes the essential role that security researchers play in improving the security of our products and the broader software ecosystem. In return for responsible disclosure in accordance with this policy, Qt Group makes the following commitments: 

No legal action for good-faith research 

Qt Group will not pursue civil or criminal legal action against researchers who discover and report vulnerabilities in good faith and in accordance with the terms of this policy. Good-faith research means accessing only systems and data necessary to demonstrate the vulnerability; avoiding actions that could harm Qt Group systems, customers, or users; not exfiltrating, modifying, or destroying data; not performing denial-of-service attacks; and coordinating disclosure with Qt Group before publishing. 

Confidentiality of reports 

Qt Group will treat vulnerability reports as confidential. Report contents will be shared only with personnel who need to know to investigate and remediate the issue, and with coordinating bodies such as NCSC-FI/Traficom and ENISA where required by law. Qt Group will not publicly attribute a report to a researcher without their explicit consent. 

Reporter credit 

Reporters who wish to be credited in the public security advisory will be acknowledged by name (or handle, as preferred) when the vulnerability is disclosed, unless the reporter requests anonymity. Qt Group will confirm the intended credit wording with the reporter before publication. 

Coordinated disclosure 

Qt Group is committed to coordinated disclosure. Reporters will be notified before any public disclosure of the vulnerability, and Qt Group will share the advisory draft with the reporter for factual review (technical accuracy of the vulnerability description) prior to publication. 

No bounty program 

Qt Group does not currently operate a monetary bug bounty program. Recognition is provided through public advisory credit as described above in Reporter credit. 

Response Commitments and SLAs 

The commitments and Service Level Agreements (SLAs) below apply to Channel A. Channel B follows the Qt Project's own process, as described below.

Channel A - psirt@qt.io (Qt Group commercial products) 

Milestone

Target

Acknowledgement of report

Within 5 business days of receipt

Status updates during remediation

Every 30 days, or upon significant change

Default coordinated disclosure embargo

90 days from verification

Public advisory and CVE publication

After 14 days of fix availability

 

Channel B - security@qt-project.org (open-source Qt components) 

Reports submitted to security@qt-project.org are reviewed by the Qt Project Core Security Team, who assess relevance and severity, work with the reporter to validate the vulnerability, and take appropriate measures to address it and prevent exploitation before releasing any necessary public disclosure. 

The Channel A timelines above represent targets. Complex vulnerabilities affecting multiple products or requiring significant architectural changes may require extended timelines. In such cases, Qt Group will communicate the reason for the extension and an updated target date to the reporter.

Embargo and Disclosure Conditions 

Default embargo 

The default embargo period is 90 days from verification. During this period, Qt Group will work to develop, test, and deploy a fix, and prepare the coordinated disclosure materials. Maintaining confidentiality during this period is part of this policy. 

Embargo extension 

If the fix cannot be completed within 90 days, Qt Group will notify the reporter with an explanation and a revised timeline. The intended process is that extensions are granted only with reporter agreement and documented justification. 

Early disclosure for active exploitation 

If evidence emerges that the vulnerability is being actively exploited in the wild, Qt Group may publish a security advisory before a fix is available. Qt Group will notify the reporter before doing so except where immediate publication is required to protect users or to fulfill regulatory obligations; for example, under Article 14 of the EU Cyber Resilience Act (CRA). 

Reporter-initiated early disclosure 

If a reporter intends to publish information about the vulnerability before the agreed disclosure date, they are asked to notify Qt Group at least seven (7) days in advance. Qt Group will make best efforts to accelerate the fix and coordinate disclosure. 

Unresponsive reporter 

Coordinating the final advisory wording with the reporter is a Qt Group commitment under Coordinated disclosure above, not a legal requirement, and it does not gate publication. The 30-day window is the period Qt Group allows a reporter to respond. Where Qt Group is unable to reach a reporter within 30 days of fix availability, it reserves the right to publish the advisory without the reporter's factual review. An unresponsive reporter will not delay publication. 

CVE Numbering Authority (CNA) 

Qt Group has been authorized as a CVE Numbering Authority (CNA) by the CVE Program, covering all Qt Group products. As a CNA, Qt Group is responsible for: 

  • Assigning CVE IDs to vulnerabilities within its CNA scope upon verification 
  • Publishing CVE records in the National Vulnerability Database (NVD) and CVE database within the timeframes required by the CVE Program 
  • Maintaining the accuracy and completeness of published CVE records 
  • Coordinating with the CVE Program on scope boundary questions 

CNA scope: All Qt Group software products with digital elements. The authoritative scope statement is registered with the CVE Program. 

Reporters will be provided with the assigned CVE ID as part of the acknowledgement of a verified vulnerability. If a reporter has already reserved a CVE ID through another CNA or Computer Emergency Response Team (CERT), Qt Group will coordinate to ensure a single CVE record is published.