How to report a bug depends on whether it has security implications.
Use GitHub’s PVR feature to report security vulnerabilities. Go to the affected repository in the NrgXnat organization, open the Security tab and click Report a vulnerability. If you’re not sure which repository is affected or the repository doesn't offer the button report it on the form below.
Do not report security vulnerabilities through public GitHub issues, discussions or pull requests, or in the XNAT Discussion Group.
If your issue doesn’t have security implications, open a GitHub issue in the affected repository: NrgXnat/xnat for XNAT core, or the repository for the affected plugin. Please search the existing issues first in case it has already been reported.
Have a question rather than a bug? Ask in the XNAT Discussion Group, where you’ll get input from our community partners in addition to the core development team.
Wherever you report it, please include a detailed description of the issue, steps to reproduce the problem and information about your environment (affected repository or plugin, XNAT/plugin version, Tomcat version, Postgres version, OS version, browser version). For security issues, also describe the potential impact. Reports lacking this detail cannot be addressed.
Do not include protected health information (PHI) or real subject data in your report, logs or screenshots. Please redact or de-identify them first.
Thanks for helping us improve the XNAT product!
Can’t report through GitHub? Send your report directly to the XNAT team.
Prefer email? You can skip this form and write to security@xnat.org directly — please include the same environment details listed above. Use email if you need to attach logs, screenshots or other files.