Per the terms of the Apache 2 license, NetBox is offered "as is" and without any guarantee or warranty pertaining to its operation. While every reasonable effort is made by its maintainers to ensure the product remains free of security vulnerabilities, users are ultimately responsible for conducting their own evaluations of each software release.
Administrators are encouraged to adhere to industry best practices concerning the secure operation of software, such as:
If you believe you've uncovered a security vulnerability and wish to report it confidentially, you may do so by emailing security@netboxlabs.com. Please ensure that your report meets all the following conditions:
Please note that we DO NOT accept reports generated by automated tooling which merely suggest that a file or file(s) may be vulnerable under certain conditions, as these are most often innocuous.
For any security concerns regarding the community-maintained Docker image for NetBox, please see the netbox-docker project.
As NetBox is provided as free open source software, we do not offer any monetary compensation for vulnerability or bug reports, however your contributions are greatly appreciated.