Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
73 changes: 73 additions & 0 deletions .github/VULNERABILITY_REPORT.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
name: Vulnerability report
description: Privately report a potential security vulnerability in CPython
body:
- type: markdown
attributes:
value: |
**Not all bugs are vulnerabilities.** Before submitting, read the [Python security policy](https://devguide.python.org/security/policy/) to understand which issues are vulnerabilities and what versions of Python accept reports.

Keep the report short and in plain text: no headers, tables, PDFs, binaries, or severity and CVSS information.

Reports that do not contain a potential security vulnerability will be discarded without a reply.

To report vulnerabilities that affect other projects (such as pip or python.org), or if you are not sure where to send your report, email [security@python.org](mailto:security@python.org).
- type: textarea
id: summary
attributes:
label: Summary
description: A few sentences describing the vulnerability.
validations:
required: true
- type: textarea
id: threat_model
attributes:
label: Threat model
description: >
What does the attacker control, and what do they gain? Describe the code, configuration, or deployment that may exist in the real world and is exploitable. Where possible, cite the relevant part of the [security policy](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities).
validations:
required: true
- type: textarea
id: proof_of_concept
attributes:
label: Proof of concept
description: >
A script that reproduces the issue and clearly indicates whether the vulnerability is present, such as exiting with `1` if vulnerable and `0` if not. If it depends on a specially constructed binary file, include a script to construct the file rather than the file itself.

Wrap scripts longer than a few lines in a [collapsed section](https://docs.github.com/en/get-started/writing-on-github/working-with-advanced-formatting/organizing-information-with-collapsed-sections) using `<details> ... </details>`.
validations:
required: true
- type: dropdown
id: versions
attributes:
label: "CPython versions tested on:"
description: >
If any tested version was not vulnerable, say which in the summary. Only [supported versions](https://devguide.python.org/versions/) accept reports.
multiple: true
options:
- "3.11"
- "3.12"
- "3.13"
- "3.14"
- "3.15"
- "3.16"
- "CPython main branch"
Comment thread
StanFromIreland marked this conversation as resolved.
validations:
required: true
- type: textarea
id: patch
attributes:
label: Suggested fix
description: Ideally, a minimal patch with the mitigation.
validations:
required: false
- type: checkboxes
id: checklist
attributes:
label: Before submitting
options:
- label: I have read the security policy and evaluated this report against it.
required: true
- label: I have checked that this issue is not already resolved on the `main` branch.
required: true
- label: I have verified the factual validity of everything in this report, including any content produced by an LLM.
required: true
Loading