Skip to main content

Security

Pigeonhole is developed and maintained by the Dovecot team with the same security standards as Dovecot itself. Security issues affect the Dovecot project as a whole, so vulnerability reporting and advisories are handled centrally.

Reporting Vulnerabilities

Found a Security Bug?

Do not report security issues via public mailing lists or public issues tracker. Please report vulnerabilities confidentially using our GPG encrypted mailbox at security@dovecot.org or via our YesWeHack Bug Bounty Program.

General Bugs

General Bug Reporting

For non-security related bugs, technical defects, or configuration issues, please consult the guidelines before submitting.

Dovecot Pro Security Advisories

Dovecot Pro is the commercial product and maintains its own security advisory program. Pro advisories may also be applicable to Dovecot and Pigeonhole Community Edition.

View Advisories