micro / micro/go-micro

[BUG] Request for private security contact — Responsible disclosure of high severity vulnerability

Open
#4,925 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
Go
Stars
23.1k
Forks
2.4k
Avg merge
1h 7m
Merged PRs (30d)
23

Description

Hi maintainers,

I have discovered a high-severity security vulnerability in the master (v6 development line) of micro/go-micro gateway dashboard.

According to SECURITY.md, security issues should NOT be reported in public GitHub issues.
The private security advisory link returns 404, and security@go-micro.dev seems undeliverable based on past discussions.

Could you please provide a working private channel (email / discord DM) so I can send the full vulnerability report, root cause, POC and remediation suggestion for coordinated disclosure?

I will not disclose any technical details publicly before a patch is released.

Thanks,
Qc

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with SECURITY.md and the private advisory link mentioned in the issue, then review the documented security contact details. Done means a working private reporting channel is available and the project documentation points to it without exposing vulnerability details publicly.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
documentation, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.