Skip to content

Security: pupnp/pupnp

SECURITY.md

Security Policy

Supported Versions

Versions currently being supported with security updates:

Version Supported
22.0.x
< 22.0.x

Reporting a Vulnerability

If you discover a security vulnerability, please do not open a public issue or PR.

Instead, report it using GitHub Private Reporting:

  1. Navigate to the "Security" tab of this repository
  2. Select "Report a vulnerability".

Please include:

  • A description of the issue.
  • Steps to reproduce (including a minimal code example).
  • Potential impact.

Our Process

This is an open source free project and as such we have our limitations.

Nonetheless, we will try to provide a fix for the problem as soon as possible and request that you do not disclose the issue publicly until we have released a patch.

If you would like to contribute the fix yourself, we do not accept public pull requests for an unpatched vulnerability, since that would expose the issue before a fix is available to users. Instead, we can set up a temporary private fork attached to the advisory so you can collaborate with us and submit your patch there directly.

Once a fix is released, we publish the advisory and request a CVE ID through GitHub.

Learn more about advisories related to pupnp/pupnp in the GitHub Advisory Database