Skip to content

Security: CyberAuth/relayldap

Security

SECURITY.md

Security Policy

Supported versions

Security fixes are made on the latest release and the main branch. Older releases may not receive separate patches.

Reporting a vulnerability

Use GitHub's private vulnerability reporting option under the repository's Security tab. Do not disclose vulnerability details in a public issue, discussion, or pull request.

If private reporting is not available, contact the maintainer through the CyberAuth GitHub profile to arrange a private channel before sharing technical details.

Include the affected version, reproduction steps, expected impact, and any suggested mitigation. Remove credentials, client names, domains, addresses, directory data, and other engagement-specific information from the report.

Reports about unintended behavior or vulnerabilities in RelayLDAP are welcome. Requests to facilitate unauthorized access, credential theft, evasion, or harmful deployment are outside the project's support scope.

There aren't any published security advisories