Hola is under active development and does not yet maintain long-term support
branches. Security fixes are applied to the latest release and to main. Please
run a recent release before reporting an issue.
Please do not open a public issue for security vulnerabilities.
Report privately through GitHub's private vulnerability reporting (Security → Advisories → Report a vulnerability). This opens a confidential advisory visible only to the maintainers.
Please include:
- a description of the vulnerability and its impact,
- the affected component (
server,web,cli,compose, or another package), - reproduction steps or a proof of concept,
- any known mitigations.
- We aim to acknowledge a report within 5 business days.
- We will keep you informed as we investigate and work on a fix.
- Once a fix is released, we are happy to credit you in the advisory unless you prefer to remain anonymous.
Thank you for helping keep Hola and its users safe.