Hello,
I have identified a security vulnerability (Denial of Service, unhandled exception) in this project's parsing logic. Since this repository does not have GitHub's private vulnerability reporting enabled, I'm opening this issue to request a private channel to share the details responsibly.
Could a maintainer please:
Enable "Private vulnerability reporting" under Settings → Security (this lets me submit a private draft security advisory directly), or
Provide a contact email where I can send the full technical report?
I have a working proof-of-concept and a suggested fix ready to share as soon as there's a private channel available.
Thank you.
Hello,
I have identified a security vulnerability (Denial of Service, unhandled exception) in this project's parsing logic. Since this repository does not have GitHub's private vulnerability reporting enabled, I'm opening this issue to request a private channel to share the details responsibly.
Could a maintainer please:
Enable "Private vulnerability reporting" under Settings → Security (this lets me submit a private draft security advisory directly), or
Provide a contact email where I can send the full technical report?
I have a working proof-of-concept and a suggested fix ready to share as soon as there's a private channel available.
Thank you.