The AeroStream team takes the security and integrity of distributed data pipelines seriously. We appreciate your efforts to responsibly disclose vulnerabilities to us.
Security updates and patches are actively maintained for the following versions:
| Version | Supported |
|---|---|
0.1.x |
✅ |
< 0.1 |
❌ |
Please DO NOT report security vulnerabilities through public GitHub issues, discussions, or pull requests.
If you believe you have discovered a vulnerability in AeroStream, please follow this disclosure process:
Submit a private report through GitHub:
- Navigate to the repository's Security tab.
- Click Report a vulnerability under Advisories.
- Provide full reproduction details.
If GitHub Private Reporting is unavailable, send an encrypted or direct email to:
contact@gradientgeeks.com- CC:
uttam-mahata-cs@outlook.com
To help us triage and resolve the issue quickly, please include:
- Description of the vulnerability (e.g., unauthorized partition access, wire protocol buffer overflow, consensus split-brain flaw).
- Affected components (
rust-broker,go-controller,ui,sdks). - Step-by-step reproduction instructions or a minimal proof-of-concept (PoC).
- Potential impact and attack vectors.
- Initial Acknowledgment: Within 48 hours of receiving your report.
- Triage & Assessment: Within 5 business days with confirmation of validity and severity rating (CVSS).
- Patch Development: We aim to deliver a fix within 30 days depending on vulnerability complexity.
- Public Disclosure: Coordinated disclosure after a patched version is published and users have reasonable time to update.
When deploying AeroStream in production:
- Enable TLS on Kafka wire port (
9092) and native port (9091). - Enforce authentication (SASL/SCRAM or mTLS) and configure RBAC / ACL policies.
- Isolate Raft consensus (port
7001) and gRPC control channels (port8001) on a private internal VPC/network. - Run broker and controller containers with unprivileged cgroup user IDs.