If you believe that you have discovered a security vulnerability in our open source software, please report it to us using the GitHub private vulnerability feature
Please do not report security vulnerabilities through public GitHub issues.
Reports should include the affected package tag, branch, or commit; a technical description of the behavior you observed; the behavior you expected; the steps required to reproduce the issue; a proof of concept or exploit, if available.
The initial acknowledgment of the report is neither an acceptance nor a rejection of the report. We may come back to you with further questions or invite you to collaborate while working through the details of your report. Resolution timelines may vary depending on the complexity and severity of the issue.
Output from automated security scans or fuzzers must include additional context demonstrating the vulnerability with a proof of concept or working exploit. Please include enough information to allow us to reproduce the issue.