5 All Nominatim releases receive security updates for two years.
 
   7 The following table lists the end of support for all currently supported
 
  10 | Version | End of support for security updates |
 
  11 | ------- | ----------------------------------- |
 
  12 | 5.1.x   | 2027-04-01                          |
 
  13 | 5.0.x   | 2027-02-06                          |
 
  14 | 4.5.x   | 2026-09-12                          |
 
  15 | 4.4.x   | 2026-03-07                          |
 
  16 | 4.3.x   | 2025-09-07                          |
 
  18 ## Reporting a Vulnerability
 
  20 If you believe, you have found an issue in Nominatim that has implications on
 
  21 security, please send a description of the issue to **security@nominatim.org**.
 
  22 You will receive an acknowledgement of your mail within 3 work days where we
 
  23 also notify you of the next steps.
 
  25 ## How we Disclose Security Issues
 
  27 ** The following section only applies to security issues found in released
 
  28 versions. Issues that concern the master development branch only will be
 
  29 fixed immediately on the branch with the corresponding PR containing the
 
  30 description of the nature and severity of the issue. **
 
  32 Patches for identified security issues are applied to all affected versions and
 
  33 new minor versions are released. At the same time we release a statement at
 
  34 the [Nominatim blog](https://nominatim.org/blog/) describing the nature of the
 
  35 incident. Announcements will also be published at the
 
  36 [geocoding mailinglist](https://lists.openstreetmap.org/listinfo/geocoding).
 
  38 ## List of Previous Incidents
 
  40 * 2023-11-20 - [SQL injection vulnerability](https://nominatim.org/2023/11/20/release-432.html)
 
  41 * 2023-02-21 - [cross-site scripting vulnerability](https://nominatim.org/2023/02/21/release-421.html)
 
  42 * 2020-05-04 - [SQL injection issue on /details endpoint](https://lists.openstreetmap.org/pipermail/geocoding/2020-May/002012.html)