Do not report security vulnerabilities in public issues, pull requests, or discussions.
For the public repository, the intended reporting path is private vulnerability reporting through the repository host. If private reporting is not yet enabled when the public remote is created, enable it before directing reporters to public issue tracking.
Until the final public remote is live, treat this file as the policy that public disclosure should wait for a private reporting channel.
Please include:
- affected component or package
- impact and attack scenario
- reproduction steps or proof of concept
- version, branch, or commit information when available
- any suggested mitigation or patch context
The most sensitive areas in ZWall Community include:
- manager and agent authentication
- token issuance, refresh, and persistence
- registration and enrollment flows
- certificate and TLS handling
- eBPF/XDP and TC enforcement behavior
- database migrations and initialization
Maintainers should acknowledge valid private reports quickly, assess impact, prepare a fix, and publish a coordinated disclosure once users have a safe upgrade path.