Skip to content

Security: StrataSource/cryptopp-modern

Security

Security.md

Security Policy

Supported Versions

We support modern versions of cryptopp-modern. Modern versions include the main branch and the latest release.

Currently supported versions:

  • 2025.12.0
  • 2025.11.0

We also incorporate critical security fixes from upstream Crypto++ and monitor for security issues in the cryptographic algorithms we implement.

Reporting a Vulnerability

You can report a security related bug in the cryptopp-modern GitHub Issues or GitHub Discussions.

For sensitive security issues, you may also contact the maintainer directly through GitHub.

If we receive a report of a security related bug then we will:

  1. Open a GitHub issue (unless the issue requires private disclosure initially)
  2. Investigate and develop a fix
  3. Release a patched version as soon as possible
  4. Credit the reporter (unless they prefer to remain anonymous)

All information will be made public after a fix is available. We do not withhold information from users because stakeholders need accurate information to assess risk and place controls to remediate the risk.

Security Updates from Upstream

cryptopp-modern monitors upstream Crypto++ for security fixes and incorporates them as appropriate. If you discover a security issue that affects both cryptopp-modern and upstream Crypto++, please report it to both projects.

There aren’t any published security advisories