Hi — I'm a security researcher (mohammad adnan, CyStack red team). I've identified what I believe is a security issue in mlserver (affecting the current release) and would like to report it privately and responsibly.
I couldn't find a private channel: this repo's GitHub Private Vulnerability Reporting appears to be disabled (Security → Advisories → Report a vulnerability returns 404) and I didn't find a SECURITY.md contact. Could you either:
- Enable Private Vulnerability Reporting (Settings → Security → Private vulnerability reporting), or
- Share a security email / preferred private channel?
I have a runtime-verified proof-of-concept and a suggested one-line fix ready to share privately. I'm deliberately not posting details here to avoid public exposure before a fix. Thank you!
Hi — I'm a security researcher (mohammad adnan, CyStack red team). I've identified what I believe is a security issue in
mlserver(affecting the current release) and would like to report it privately and responsibly.I couldn't find a private channel: this repo's GitHub Private Vulnerability Reporting appears to be disabled (Security → Advisories → Report a vulnerability returns 404) and I didn't find a SECURITY.md contact. Could you either:
I have a runtime-verified proof-of-concept and a suggested one-line fix ready to share privately. I'm deliberately not posting details here to avoid public exposure before a fix. Thank you!