GET /cna
CVE coordination
Prospective CNAPublic scope, reporting contact, disclosure policy, and advisory location for my CVE Numbering Authority application.
Scope
Vulnerabilities in the open-source projects listed below when I am an authorized maintainer or security coordinator; and vulnerabilities in other open-source projects that I research or coordinate when an authorized project representative explicitly requests my assistance, provided the vulnerability is not already covered by another CNA with more appropriate scope.
Supported and end-of-life releases are considered case by case. I will defer to the supplier or another CNA whenever it has more appropriate scope.
Reporting and public contact
Report vulnerabilities through the affected project's private reporting channel first. On GitHub, open the project's Security tab and use Report a vulnerability when available. Do not open a public issue.
If the project has no private reporting channel, or for CNA coordination, contact [email protected].
Disclosure policy
Reports are handled privately with the reporter and the affected project. I will validate the issue, identify affected versions, check for duplicate CVE records, and coordinate a fix and disclosure date with the relevant maintainers.
A fix or mitigation should be available before or at disclosure whenever feasible. Published information will include affected and fixed versions, impact, mitigations, references, and reporter credit when requested. Timelines may be shortened for active exploitation or adjusted when necessary to protect users. The current CNA Operational Rules take precedence.
Advisory location
Formal advisories are published through the affected project's canonical public security-advisory page and will be indexed here after disclosure. Published advisories will be readable without login.
No published advisories are currently listed.