From c2da1cb40793864e272d48f8400d22dae0957a71 Mon Sep 17 00:00:00 2001 From: Stan Ulbrych Date: Fri, 2 Oct 2026 18:05:17 +0100 Subject: [PATCH 1/4] Draft `VULNERABILITY_REPORT.yml` --- .github/VULNERABILITY_REPORT.yml | 80 ++++++++++++++++++++++++++++++++ 1 file changed, 80 insertions(+) create mode 100644 .github/VULNERABILITY_REPORT.yml diff --git a/.github/VULNERABILITY_REPORT.yml b/.github/VULNERABILITY_REPORT.yml new file mode 100644 index 00000000000000..f7e2ed90c1a9b4 --- /dev/null +++ b/.github/VULNERABILITY_REPORT.yml @@ -0,0 +1,80 @@ +name: Vulnerability report +description: Privately report a potential security vulnerability in CPython +body: + - type: markdown + attributes: + value: | + > [!IMPORTANT] Not all bugs are vulnerabilities. Read the [Python security + > policy](https://devguide.python.org/security/policy/) + > before submitting, and evaluate your report against [what types of + > bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) + > and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). + + Python Security Response Team (*PSRT*) members balance this work against + many other responsibilities. Keep the report short and in plain text: + no headers, tables, PDFs, binaries, or severity and CVSS information. + + Reports that do not contain a potential security vulnerability will be + discarded without a reply. + + This form is for CPython only. For other projects (such as pip or + python.org), or if you are not sure where to send your report, email + [security@python.org](mailto:security@python.org). + - type: textarea + id: summary + attributes: + label: Summary + description: A few sentences describing the vulnerability. + validations: + required: true + - type: textarea + id: threat_model + attributes: + label: Threat model + description: > + What does the attacker control, and what do they gain? + Describe the code, configuration, or deployment that may exist in the real world and is exploitable. + Where possible, cite the relevant part of the + [security policy](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities). + validations: + required: true + - type: textarea + id: proof_of_concept + attributes: + label: Proof of concept + description: > + A script that reproduces the issue and clearly indicates whether the vulnerability is present, + such as exiting with `1` if vulnerable and `0` if not. + If it depends on a specially constructed binary file, include a script to construct the file rather than the file itself. + Wrap scripts longer than a few lines in a + [collapsed section](https://docs.github.com/en/get-started/writing-on-github/working-with-advanced-formatting/organizing-information-with-collapsed-sections) + using `
...
`. + validations: + required: true + - type: input + id: versions + attributes: + label: Python versions tested + description: > + List every version tested and indicate which were found to be vulnerable. + Only [supported versions](https://devguide.python.org/versions/) accept reports. + validations: + required: true + - type: textarea + id: patch + attributes: + label: Suggested fix + description: Ideally, a minimal patch with the mitigation. + validations: + required: false + - type: checkboxes + id: checklist + attributes: + label: Before submitting + options: + - label: I have read the security policy and evaluated this report against it. + required: true + - label: I have checked that this issue is not already resolved on the `main` branch. + required: true + - label: I have verified the factual validity of everything in this report, including any content produced by an LLM. + required: true From 85a3101ff9bc30cdfc6592dd505e1923f9fc6e56 Mon Sep 17 00:00:00 2001 From: Stan Ulbrych Date: Fri, 2 Oct 2026 18:09:17 +0100 Subject: [PATCH 2/4] Use only rudimentary formatting --- .github/VULNERABILITY_REPORT.yml | 34 +++++++++----------------------- 1 file changed, 9 insertions(+), 25 deletions(-) diff --git a/.github/VULNERABILITY_REPORT.yml b/.github/VULNERABILITY_REPORT.yml index f7e2ed90c1a9b4..049b2a06eb5733 100644 --- a/.github/VULNERABILITY_REPORT.yml +++ b/.github/VULNERABILITY_REPORT.yml @@ -4,22 +4,13 @@ body: - type: markdown attributes: value: | - > [!IMPORTANT] Not all bugs are vulnerabilities. Read the [Python security - > policy](https://devguide.python.org/security/policy/) - > before submitting, and evaluate your report against [what types of - > bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) - > and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). + **Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). - Python Security Response Team (*PSRT*) members balance this work against - many other responsibilities. Keep the report short and in plain text: - no headers, tables, PDFs, binaries, or severity and CVSS information. + Python Security Response Team (*PSRT*) members balance this work against many other responsibilities. Keep the report short and in plain text: no headers, tables, PDFs, binaries, or severity and CVSS information. - Reports that do not contain a potential security vulnerability will be - discarded without a reply. + Reports that do not contain a potential security vulnerability will be discarded without a reply. - This form is for CPython only. For other projects (such as pip or - python.org), or if you are not sure where to send your report, email - [security@python.org](mailto:security@python.org). + This form is for CPython only. For other projects (such as pip or python.org), or if you are not sure where to send your report, email [security@python.org](mailto:security@python.org). - type: textarea id: summary attributes: @@ -32,10 +23,7 @@ body: attributes: label: Threat model description: > - What does the attacker control, and what do they gain? - Describe the code, configuration, or deployment that may exist in the real world and is exploitable. - Where possible, cite the relevant part of the - [security policy](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities). + What does the attacker control, and what do they gain? Describe the code, configuration, or deployment that may exist in the real world and is exploitable. Where possible, cite the relevant part of the [security policy](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities). validations: required: true - type: textarea @@ -43,12 +31,9 @@ body: attributes: label: Proof of concept description: > - A script that reproduces the issue and clearly indicates whether the vulnerability is present, - such as exiting with `1` if vulnerable and `0` if not. - If it depends on a specially constructed binary file, include a script to construct the file rather than the file itself. - Wrap scripts longer than a few lines in a - [collapsed section](https://docs.github.com/en/get-started/writing-on-github/working-with-advanced-formatting/organizing-information-with-collapsed-sections) - using `
...
`. + A script that reproduces the issue and clearly indicates whether the vulnerability is present, such as exiting with `1` if vulnerable and `0` if not. If it depends on a specially constructed binary file, include a script to construct the file rather than the file itself. + + Wrap scripts longer than a few lines in a [collapsed section](https://docs.github.com/en/get-started/writing-on-github/working-with-advanced-formatting/organizing-information-with-collapsed-sections) using `
...
`. validations: required: true - type: input @@ -56,8 +41,7 @@ body: attributes: label: Python versions tested description: > - List every version tested and indicate which were found to be vulnerable. - Only [supported versions](https://devguide.python.org/versions/) accept reports. + List every version tested and indicate which were found to be vulnerable. Only [supported versions](https://devguide.python.org/versions/) accept reports. validations: required: true - type: textarea From 432f3da20f7125c64c35a68486aaec5089361617 Mon Sep 17 00:00:00 2001 From: Stan Ulbrych Date: Fri, 2 Oct 2026 18:14:01 +0100 Subject: [PATCH 3/4] Use selector for Python version --- .github/VULNERABILITY_REPORT.yml | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/.github/VULNERABILITY_REPORT.yml b/.github/VULNERABILITY_REPORT.yml index 049b2a06eb5733..1090eccbfe46fd 100644 --- a/.github/VULNERABILITY_REPORT.yml +++ b/.github/VULNERABILITY_REPORT.yml @@ -36,12 +36,21 @@ body: Wrap scripts longer than a few lines in a [collapsed section](https://docs.github.com/en/get-started/writing-on-github/working-with-advanced-formatting/organizing-information-with-collapsed-sections) using `
...
`. validations: required: true - - type: input + - type: dropdown id: versions attributes: - label: Python versions tested + label: "CPython versions tested on:" description: > - List every version tested and indicate which were found to be vulnerable. Only [supported versions](https://devguide.python.org/versions/) accept reports. + If any tested version was not vulnerable, say which in the summary. Only [supported versions](https://devguide.python.org/versions/) accept reports. + multiple: true + options: + - "3.11" + - "3.12" + - "3.13" + - "3.14" + - "3.15" + - "3.16" + - "CPython main branch" validations: required: true - type: textarea From d3dc99bae410f085267f82419e5c652fa3c4fb05 Mon Sep 17 00:00:00 2001 From: Stan Ulbrych Date: Fri, 2 Oct 2026 20:16:20 +0100 Subject: [PATCH 4/4] Apply Ezio's suggestiosn Co-authored-by: Ezio Melotti --- .github/VULNERABILITY_REPORT.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.github/VULNERABILITY_REPORT.yml b/.github/VULNERABILITY_REPORT.yml index 1090eccbfe46fd..2887c7092d19fe 100644 --- a/.github/VULNERABILITY_REPORT.yml +++ b/.github/VULNERABILITY_REPORT.yml @@ -4,13 +4,13 @@ body: - type: markdown attributes: value: | - **Not all bugs are vulnerabilities.** Read the [Python security policy](https://devguide.python.org/security/policy/) before submitting, and evaluate your report against [what types of bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). + **Not all bugs are vulnerabilities.** Before submitting, read the [Python security policy](https://devguide.python.org/security/policy/) to understand which issues are vulnerabilities and what versions of Python accept reports. - Python Security Response Team (*PSRT*) members balance this work against many other responsibilities. Keep the report short and in plain text: no headers, tables, PDFs, binaries, or severity and CVSS information. + Keep the report short and in plain text: no headers, tables, PDFs, binaries, or severity and CVSS information. Reports that do not contain a potential security vulnerability will be discarded without a reply. - This form is for CPython only. For other projects (such as pip or python.org), or if you are not sure where to send your report, email [security@python.org](mailto:security@python.org). + To report vulnerabilities that affect other projects (such as pip or python.org), or if you are not sure where to send your report, email [security@python.org](mailto:security@python.org). - type: textarea id: summary attributes: