We officially support and patch only the latest minor release of pqc-proxy. Security fixes will not be backported to older legacy versions.
Do not open a public GitHub Issue for security-related bugs.
If you discover a security vulnerability (such as a memory leak, encryption bypass, or parser flaw), please report it responsibly by using one of the following methods:
- GitHub Private Vulnerability Reporting: Navigate to the "Security" tab of this repository, click on "Advisories", and select "Report a vulnerability".
- Direct Email: Send a detailed report to bugs@ventie.dev.
Please include the following information in your report:
- A detailed description of the vulnerability and its potential impact.
- Step-by-step instructions or a minimal proof-of-concept (PoC) to reproduce the issue.
- Any potential mitigation steps you have identified.
- Acknowledgment: We will acknowledge receipt of your report within 48 hours.
- Triage: We will investigate and validate the vulnerability within 7 days.
- Resolution: If validated, we will coordinate a fix and release a patch version.
- Disclosure: A public security advisory will be published alongside the patch release, crediting you for the discovery unless you prefer to remain anonymous.