D(HE)ater is a proof-of-concept tool that demonstrates the D(HE)at attack (CVE-2002-20001). This policy covers vulnerabilities in D(HE)ater itself — not the protocol weakness it demonstrates, which is documented on the official project site.
Security fixes are provided for the latest released version only. Please reproduce any issue against the most recent release on PyPI before reporting it.
| Version | Supported |
|---|---|
| 0.4.x | ✅ |
| < 0.4 | ❌ |
Report security issues privately — do not open a public issue for an undisclosed vulnerability.
- Email: coroner@pfeifferszilard.hu
- Alternatively, open a confidential issue on GitLab (tick This issue is confidential) or a private security advisory on GitHub.
Please include the affected version, the platform and Python version, steps to reproduce, and the impact. You can expect an acknowledgement within a few days. Once a fix is available, the vulnerability will be disclosed together with the release that addresses it.
D(HE)ater performs a real denial-of-service attack. Use it only against systems you own or are explicitly authorized to test. Unauthorized use may be illegal and will disrupt the targeted service. See the disclaimer in the README for details.