Security

Responsible Disclosure

We take the security of our systems and our clients' data seriously. If you've discovered a vulnerability, we want to hear from you — and we'll work with you to resolve it quickly.

Report a vulnerability

Estimated severity

By submitting this form you agree to our Privacy Policy. Please do not use this form to report general bugs or feature requests — use our contact page for those.

Transparency

Disclosed Vulnerabilities

We publicly disclose resolved vulnerabilities to promote transparency and help the wider security community.

  • Medium

    Reflected XSS in contact form error message

    Unsanitised query parameter was reflected in a validation error message, allowing script injection via a crafted URL.

    Website (galaxen.co)

    12 Apr 2026

    Fixed
  • Low

    Open redirect on post-authentication callback

    The redirect_to parameter after login was not validated against an allowlist, enabling phishing via a redirect to an external domain.

    Client Portal

    28 Apr 2026

    Fixed
  • High

    API rate-limiting bypass via header spoofing

    Forwarding the X-Forwarded-For header to a loopback address circumvented per-IP rate limits on the public API.

    API

    3 Jun 2026

    Investigating

Prefer to email?

Send encrypted reports directly to our security team.

security@galaxen.co