Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY] Vulnerability in nanohttpd #620

Open
JLLeitschuh opened this issue Jan 28, 2022 · 0 comments
Open

[SECURITY] Vulnerability in nanohttpd #620

JLLeitschuh opened this issue Jan 28, 2022 · 0 comments

Comments

@JLLeitschuh
Copy link

JLLeitschuh commented Jan 28, 2022

I'd like to report a security vulnerability in nanohttpd. If a maintainer could kindly provide a list of GitHub usernames to include in a GitHub security advisory, I'd be happy to discuss this vulnerability privately.

GHSA-2r85-x9cf-8fcg

If instead you'd like to disclose this vulnerability under this project, please don't hesitate to create a GitHub Security advisory under this repository:

https://github.com/NanoHttpd/nanohttpd/security/advisories

This vulnerability disclosure follows Google's 90-day vulnerability disclosure policy (I'm not an employee of Google, I just like their policy). Full disclosure will occur either at the end of the 90-day deadline or whenever a patch is made widely available, whichever occurs first.

If I don't hear from a maintainer in 30 days, this vulnerability will automatically become public and a CVE with no-fix-available will be automatically issued.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant