Please report suspected vulnerabilities privately through GitHub Security Advisories. Do not open a public issue, discussion, or pull request.
- Open the link above and select Report a vulnerability.
- Include a clear description of the issue, affected versions or commits, steps to reproduce, impact, and a proof of concept where safe to provide one.
- Submit the report. The report becomes a draft repository security advisory that is visible only to repository maintainers and invited collaborators.
- Use the advisory's private discussion to answer questions and coordinate disclosure. Please give us reasonable time to investigate and release a fix before disclosing the issue publicly.
Repository maintainers use the draft advisory to coordinate remediation without exposing the vulnerability before users can update:
- Review and accept the private report in Security > Advisories, then communicate with the reporter in the advisory.
- Invite only the people needed to investigate and fix the issue. If code changes must remain private, create the advisory's temporary private fork and develop the fix there.
- Test the fix, release a patched version, and record the affected and patched versions in the advisory.
- Complete the advisory with a summary, impact, severity, CWE where applicable, CVSS details, credits, and mitigation or upgrade guidance. Request a CVE from GitHub when appropriate.
- Publish the advisory after the fix is available. Publishing discloses the vulnerability to the community and gives users the information they need to assess impact and upgrade.
We will credit reporters unless they prefer to remain anonymous.