Skip to content

Security vulnerability report — requesting private contact #41

Description

@0xgus1337

Hello,

I have identified a security vulnerability (Denial of Service, unhandled exception) in this project's parsing logic. Since this repository does not have GitHub's private vulnerability reporting enabled, I'm opening this issue to request a private channel to share the details responsibly.

Could a maintainer please:

Enable "Private vulnerability reporting" under Settings → Security (this lets me submit a private draft security advisory directly), or
Provide a contact email where I can send the full technical report?

I have a working proof-of-concept and a suggested fix ready to share as soon as there's a private channel available.

Thank you.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions