apache / apache/incubator-seata

[Security Follow-up] Request for status update on private report submitted on August 2, 2026

Open
#8,225 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
26k
Forks
8.8k
Avg merge
1d 8h
Merged PRs (30d)
4

Description

### Check Ahead

- [x] I have searched the [issues](https://github.com/seata/seata/issues) of this repository and believe that this is not a duplicate.

- [x] I am willing to try to fix this bug myself.

### Ⅰ. Issue Description

Hello Seata team,

I am writing to respectfully follow up on a private security report that I submitted to the Apache Security Team on August 2, 2026.

Timeline:

- August 2, 2026: Initial private report submitted to security@apache.org, with private@seata.apache.org copied.
- August 31, 2026: Follow-up sent to the Apache Security Team.
- August 31, 2026: A Seata maintainer confirmed that the report had been received and would be coordinated with the PMC.
- September 6, 2026: Follow-up request sent.
- September 9, 2026: Additional follow-up request sent.
- September 14, 2026: I have not yet received a further status update or tracking information.

For reference, I previously opened a status follow-up in #8213:
https://github.com/apache/incubator-seata/issues/8213

I understand that security-related matters may require private handling and coordination. I have followed the ASF responsible-disclosure process and will continue to respect the project’s preferred procedures.

Could you please confirm whether the report is being handled by the appropriate team, and let me know whether any further information or assistance is needed from me?

This report is part of my ongoing research. If you have any questions, please feel free to @mention me at any time. I would be very happy to provide assistance and contribute to improving Seata’s security.

Thank you for your time and assistance.

Best regards,

### Ⅱ. Describe what happened

_No response_

### Ⅲ. Describe what you expected to happen

_No response_

### Ⅳ. How to reproduce it (as minimally and precisely as possible)

_No response_

### Ⅴ. Anything else we need to know?

_No response_

### Ⅵ. Environment

_No response_

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the linked prior follow-up in issue #8213 and the private security-report correspondence referenced in this issue. No source files, tests, or entry points are identified; done means confirming the report's handling or receiving the requested status and tracking information.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.