Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Instead, report them privately via GitHub's private vulnerability reporting (the "Report a vulnerability" button on the repository's Security tab).
Please include as much of the following as you can:
- A description of the issue and its impact (e.g. authentication bypass, filter bypass, data exposure)
- Steps to reproduce, ideally with a minimal configuration and example requests
- Affected version(s) and relevant configuration (e.g. enabled filters, upstream STAC API)
- Any suggested fix or mitigation
- We aim to acknowledge reports within 5 business days.
- We will keep you informed as we investigate and work on a fix.
- Once a fix is released, we will publish a GitHub Security Advisory and, where appropriate, request a CVE. Reporters are credited unless they prefer to remain anonymous.
Please give us a reasonable amount of time to address the issue before any public disclosure.
Security fixes are applied to the latest release only. Please upgrade to the most recent version before reporting.