Skip to content

Security: aio-libs/aiohttp

SECURITY.md

Tip

We encourage responsible disclosure practices for security issues. This document explains how to share your concerns with us.

Reporting Vulnerabilities

Caution

Please do not make public announcements/discussions/issues/posts about potential vulnerabilities on GitHub or any other spaces!

⚠️ They must not be open for everyone to see ⚠️

Before reporting a vulnerability

  1. If this repository contains THREAT_MODEL.md please refer to it first to understand if your vulnerability is valid and in-scope.
  2. If this repository contains SECURITY_EXTRA.md please refer to it and follow any additional directions specific to this repository.
  3. When writing the report, please use Github permalinks when referencing any code in the project.
  4. With understanding that this is open source software provided for free and you might not receive a timely response, please consider encouraging your employer to support the project maintenance via GH Sponsors badge

Reporting a Vulnerability

If you believe you've found a security-related bug, fill out a new vulnerability report via GitHub directly. To do so, follow these instructions:

  1. Click on the Security tab in the project repository.
  2. Click the green Report a vulnerability button at the top right corner.
  3. Fill in the form as accurately as you can, including as many details as possible.
  4. Click the green Submit report button at the bottom.

Don't Have a GitHub Account?

Alternatively, drop an email to our aio-libs security mailbox instead of filing a ticket or posting to any public groups. It is currently set up to forward every incoming letter to Andrew Svetlov, Sam Bull and Sviatoslav Sydorenko. You can choose to email us directly as well. We will try to assess the problem in timely manner and disclose it in a responsible way.