Skip to content

Security: gen0sec/synapse

SECURITY.md

Security Policy

Supported Versions

Version Supported
latest

Reporting a Vulnerability

If you discover a security vulnerability in Synapse, please report it responsibly:

  1. Email: Send details to security@gen0sec.com
  2. Do NOT open a public GitHub issue for security vulnerabilities
  3. Include as much detail as possible:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if any)

Response Timeline

  • Acknowledgment: Within 48 hours of report
  • Initial assessment: Within 5 business days
  • Fix timeline: Critical issues within 7 days, High within 30 days

Scope

The following are in scope for security reports:

  • Synapse reverse proxy core
  • eBPF/XDP firewall components
  • TLS termination and certificate management
  • WAF rule engine
  • Authentication and access control
  • Configuration parsing (path traversal, injection)

Out of Scope

  • Denial of service via legitimate traffic volume
  • Issues in third-party dependencies (report upstream, but notify us)
  • Issues requiring physical access to the server

Disclosure Policy

We follow coordinated disclosure. We ask that you:

  • Allow us reasonable time to fix the issue before public disclosure
  • Do not exploit the vulnerability beyond what is necessary to demonstrate it

There aren’t any published security advisories