Pylons / Pylons/webob

Security: request to open a private disclosure channel

Open
#499 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
443
Forks
206
PR merge metrics
No merged PRs in 30d

Description

Hi — I'm a security researcher (mohammad adnan, CyStack red team). I've identified what I believe is a security issue in WebOb (affecting the current release) and would like to report it privately and responsibly. (Pylons Project may prefer its security list — happy to use that.)

I couldn't find a private channel here: this repo's GitHub Private Vulnerability Reporting appears to be disabled (Security → Advisories → Report a vulnerability returns 404). Could you either:

  1. Enable Private Vulnerability Reporting (Settings → Security → Private vulnerability reporting), or
  2. Point me to the Pylons security contact / preferred private channel?

I have a runtime-verified proof-of-concept and a suggested one-line fix ready to share privately. I'm deliberately not posting details here to avoid public exposure before a fix. Thank you!

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

This issue names no source files or tests and intentionally withholds the proof of concept. First review the repository's Security settings and the Pylons security contact options mentioned in the report. Done means enabling private vulnerability reporting or documenting the preferred private channel so the researcher can share the details safely.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.