If you discover a security vulnerability in image-proxy, please report it privately.
Do not open a public GitHub issue. Instead, send a detailed report to the repository owner via the Security tab at:
https://github.com/schiz0x00/image-proxy/security/advisories/new
You should receive a response within 48 hours. If you do not, please follow up.
This project is an image proxy — it makes HTTP requests to arbitrary URLs on behalf of clients. Vulnerabilities related to SSRF, information disclosure, resource exhaustion, or authentication bypass are considered in-scope.
Only the latest tagged release receives security patches.