Skip to content

Security

We take security seriously and use various measures to ensure the safety of our products. Our security policies include:

  • Regular vulnerability scanning using industry-standard tools.
  • We treat vulnerabilities reports as our priority. This means that we attempt to fix them as quickly as possible, therefore, we will release a hotfix for any major security vulnerability found in the most recent version of our SDK/server.
  • We only use reputable 3rd party libraries and update them regularly

Reporting a Vulnerability

If you discover a security vulnerability, please report it to us by submitting a request in our Service Desk Portal. Include the details of the vulnerability, affected versions, and any known mitigations.

Vulnerability Scanning

We run vulnerability scans periodically on all components of our product. We use both open-source and proprietary vulnerability scanners such as Wiz.

CVE History

Below is a table of the latest CVEs we have fixed:

CVE Severity Type Fixed Version
CVE-2026-33870 HIGH Java 2.5.4
CVE-2026-33871 HIGH Java 2.5.4
CVE-2026-0915 MEDIUM System 2.5.3
CVE-2026-0861 MEDIUM System 2.5.3
CVE-2025-15281 MEDIUM System 2.5.3
CVE-2026-21933 MEDIUM Java 2.5.3
CVE-2026-21945 MEDIUM Java 2.5.3
CVE-2026-21932 MEDIUM Java 2.5.3
GHSA-72hv-8253-57qq HIGH Java 2.5.3
CVE-2026-3805 HIGH System 2.5.3
CVE-2026-1965 MEDIUM System 2.5.3
CVE-2026-3783 MEDIUM System 2.5.3
CVE-2026-22732 CRITICAL Java 2.5.2
CVE-2025-53057 MEDIUM Java 2.5.2
CVE-2025-53066 MEDIUM Java 2.5.2
CVE-2026-21925 MEDIUM Java 2.5.1
CVE-2026-24880 HIGH Java 2.5.1
CVE-2026-34487 HIGH Java 2.5.1
CVE-2026-34483 HIGH Java 2.5.1
CVE-2026-29145 CRITICAL Java 2.5.1
CVE-2025-55752 HIGH Java 2.5.1
CVE-2025-24734 HIGH Java 2.5.1

Non-fixable CVEs

In this section, we list the CVEs that are currently classified as non-fixable. These vulnerabilities have been thoroughly assessed, and due to various constraints, have not been resolved.

We continuously monitor these CVEs and work towards finding feasible solutions.

CVE Severity Type Description
CVE-2022-27943 Low System https://ubuntu.com/security/CVE-2022-27943