Security: request to open a private disclosure channel
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 443
- Forks
- 206
- PR merge metrics
- No merged PRs in 30d
Description
Hi — I'm a security researcher (mohammad adnan, CyStack red team). I've identified what I believe is a security issue in WebOb (affecting the current release) and would like to report it privately and responsibly. (Pylons Project may prefer its security list — happy to use that.)
I couldn't find a private channel here: this repo's GitHub Private Vulnerability Reporting appears to be disabled (Security → Advisories → Report a vulnerability returns 404). Could you either:
- Enable Private Vulnerability Reporting (Settings → Security → Private vulnerability reporting), or
- Point me to the Pylons security contact / preferred private channel?
I have a runtime-verified proof-of-concept and a suggested one-line fix ready to share privately. I'm deliberately not posting details here to avoid public exposure before a fix. Thank you!
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
This issue names no source files or tests and intentionally withholds the proof of concept. First review the repository's Security settings and the Pylons security contact options mentioned in the report. Done means enabling private vulnerability reporting or documenting the preferred private channel so the researcher can share the details safely.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100