Do not use public issues, pull requests, or project discussions to report vulnerabilities, active investigations, imminent threats, personal data, child-safety concerns, or any other sensitive material.
For a repository-security issue, use GitHub private vulnerability reporting if it is enabled, or contact the current project leaders through the contact route published on the OWASP project page. Include only the minimum information needed to establish the issue.
This documentation project is not an emergency service, investigative body, or reporting channel for suspected criminal activity. Use the appropriate local emergency, law-enforcement, child-protection, or organisational safeguarding channel for urgent risks.