The XARF project takes security vulnerabilities seriously. We appreciate your efforts to responsibly disclose your findings.
Please DO NOT report security vulnerabilities through public GitHub issues.
Instead, please report security vulnerabilities by emailing:
Please include the following information in your report:
- Type of vulnerability or security concern
- Affected specification version(s)
- Detailed description of the security issue
- Potential impact on implementations
- Suggested mitigation or fix (if applicable)
- Initial Response: Within 48 hours
- Status Update: Within 7 days
- Resolution: Depends on severity and complexity
- Triage: We'll confirm the vulnerability and assess severity
- Specification Review: We'll review affected specification sections
- Fix Development: We'll develop and review proposed changes
- Community Review: We'll engage with implementation maintainers
- Disclosure: We'll coordinate disclosure timing with you
- Publication: We'll publish updated specification with security notes
We follow a coordinated disclosure model:
- Private Disclosure: Report sent to security@abusix.com
- Acknowledgment: We confirm receipt within 48 hours
- Investigation: We investigate with specification experts
- Community Review: We consult with implementation maintainers
- Specification Update: We publish updated specification
- Public Disclosure: We publish advisory 7 days after publication
We recognize security researchers who responsibly disclose vulnerabilities:
No vulnerabilities reported yet.