Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in this project, please report it responsibly.

Email: david@balneariodecofrentes.es

Please include:

We will acknowledge receipt within 48 hours and aim to provide a fix or mitigation within 7 days for critical issues.

Security Considerations

DIMSE-Specific Risks

TLS / DICOM Secure Transport (v0.6.0+)

v0.6.0 added native TLS support via OTP :ssl and Ranch SSL (PS3.15 Annex B). TLS mitigates plaintext DIMSE traffic exposure and, with mutual TLS (mTLS), client AE title spoofing. See the README for usage examples.

Supported Versions

Version Supported
0.6.x Yes
0.5.x Yes
< 0.5 No