~/marcelotryle

GET /cna

CVE coordination

Prospective CNA

Public scope, reporting contact, disclosure policy, and advisory location for my CVE Numbering Authority application.

Scope

Vulnerabilities in the open-source projects listed below when I am an authorized maintainer or security coordinator; and vulnerabilities in other open-source projects that I research or coordinate when an authorized project representative explicitly requests my assistance, provided the vulnerability is not already covered by another CNA with more appropriate scope.

Supported and end-of-life releases are considered case by case. I will defer to the supplier or another CNA whenever it has more appropriate scope.

Reporting and public contact

Report vulnerabilities through the affected project's private reporting channel first. On GitHub, open the project's Security tab and use Report a vulnerability when available. Do not open a public issue.

If the project has no private reporting channel, or for CNA coordination, contact [email protected].

Disclosure policy

Reports are handled privately with the reporter and the affected project. I will validate the issue, identify affected versions, check for duplicate CVE records, and coordinate a fix and disclosure date with the relevant maintainers.

A fix or mitigation should be available before or at disclosure whenever feasible. Published information will include affected and fixed versions, impact, mitigations, references, and reporter credit when requested. Timelines may be shortened for active exploitation or adjusted when necessary to protect users. The current CNA Operational Rules take precedence.

Advisory location

Formal advisories are published through the affected project's canonical public security-advisory page and will be indexed here after disclosure. Published advisories will be readable without login.

No published advisories are currently listed.