How to report a bug or vulnerability
Last updated:
Found a bug or vulnerability? Here's how you can securely report it directly to us, and what happens after you do. This page is also our coordinated vulnerability disclosure policy.
Use email for non-sensitive issues or general enquiries
Just send an email to support@mullvadvpn.net
Use encrypted email for more sensitive issues
If you've found a sensitive vulnerability and want to contact us in a secure and private manner, then send us a PGP-encrypted email to support@mullvadvpn.net using our public key.
Don't know how to do that? Follow our guide on using encrypted email.
What to put in your report
The more we can reproduce, the sooner we can fix it. If you can, tell us:
- What the problem is, what someone could do with it, and who it affects.
- Where you found it (app, browser, platform, version) and any relevant API endpoint(s) or website URL(s).
- The steps to reproduce it. Proof-of-concept code helps a lot.
- Whether you have any reason to think someone is already exploiting it. Tell us this first if you do, because it changes how quickly we have to act.
- Anything you think would fix it, if you have an idea.
Send us what you have. A half-finished report is far better than no report.
What happens next
A person reads your report and gets back to you. If we think you've found something real, we'll say so. If we think you haven't, we'll tell you why. We would much rather be argued with than be quietly wrong.
After that we work on a fix. We'll tell you when it ships, and we publish what happened once it has. If you would like credit for the find, we'll name you. If you would rather stay anonymous, that's fine too.
One thing you should know up front: if we find that a vulnerability is already being exploited against people, EU law now requires us to report it to ENISA and the Swedish national CSIRT while we fix it. We'll tell you if that happens to your report.
What we ask of you
Please hold off on publishing until a fix exists. Our aim is 90 days from the day you report, and we'll agree a date with you rather than impose one. That can be shorter if people are actively being attacked, or longer if the fix is genuinely hard and you're willing to wait.
Please don't test against other people's accounts, data or traffic. Use your own.
Please do not perform destructive testing or automated high-volume scanning against our production infrastructure.
Send via the app
If you encounter an issue while using the Mullvad VPN app, you can easily notify us directly from within the app. In the Settings menu, click on Report a problem (under Support in the desktop app) and send your find to us. You don't need to fill in an email address, but if you want a reply from us, you will need to include one. As the form states, your app's log files are anonymized before being securely sent to us.

Bounty for bugs?
We have no bug bounty program, but we greatly appreciate the goodwill of customers who take the time to share their finds with us. Whether it's a tiny bug that you've found and helped us squash or a slightly larger, hairier, uglier vulnerability that needs special attention, all reports help us to continuously improve our service for everyone.
Legal statement
Mullvad VPN will not pursue legal actions against security researchers that reports bugs or vulnerabilities to us. (And we think it’s sad we even have to state this.)