codeskyblue / codeskyblue/gohttpserver

Security: Please enable Private Vulnerability Reporting

Open
#232 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
2.8k
Forks
583
PR merge metrics
No merged PRs in 30d

Description

Hi @codeskyblue,

I am a security researcher and I have identified **two critical security vulnerabilities** in gohttpserver that I would like to report responsibly.

However, [Private Vulnerability Reporting](https://docs.github.com/en/code-security/security-advisories/guidance-on-reporting-and-writing-information-about-vulnerabilities/privately-reporting-a-security-vulnerability) is not currently enabled on this repository, so I cannot submit a confidential security advisory through GitHub.

**Could you please enable Private Vulnerability Reporting?** You can do this from:
**Settings > Security > Private vulnerability reporting > Enable**

This will allow me to submit the full details, proof of concept, and suggested fixes privately, so the vulnerabilities can be patched before any public disclosure.

I have also sent the details to your email address for immediate review.

Thank you for your time.

Dennis Sepede
[Securitix Solutions](https://securitixsolutions.com)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.