Vulnerability Disclosure Policy

Stand: 2026-08-11

Security vulnerabilities on the website or in programs of gaijin.at can be reported confidentially to web@gaijin.at.

Communication is exclusively via email in German or English. Generally, every incoming report will be answered within one week. A response may be withheld if the reported vulnerability is not security-relevant, is already known, or cannot be reproduced.

Reports without a valid email address for follow-up questions may not be processed or may only be processed inadequately.

The report should include at least the following:

No legal action will be taken against the person reporting a vulnerability, provided this policy is followed. This does not apply if there is or was obvious criminal intent.

The following actions are not permitted: