Tip
We encourage responsible disclosure practices for security issues. This document explains how to share your concerns with us.
Caution
Please do not make public announcements/discussions/issues/posts about potential vulnerabilities on GitHub or any other spaces!
- When writing the report, please use Github permalinks when referencing any code in the project.
If you believe you've found a security-related bug, fill out a new vulnerability report via GitHub directly. To do so, follow these instructions:
- Click on the
Securitytab in the project repository. - Click the green
Report a vulnerabilitybutton at the top right corner. - Fill in the form as accurately as you can, including as many details as possible.
- Click the green
Submit reportbutton at the bottom.
Alternatively, email Taras Kozlov or use the aio-libs security mailbox instead of filing a ticket or posting to any public groups. We will try to assess the problem in a timely manner and disclose it responsibly.