If you discover a potential security vulnerability or AI security concern in PixelUMM, report it privately through NVIDIA's security and AI concern reporting page or by email to NVIDIA PSIRT. Do not disclose security issues in public GitHub issues, pull requests, or discussions.
If reporting by email, use NVIDIA's public PGP key to encrypt the report. Include the affected PixelUMM version or commit, the vulnerability type, steps to reproduce, a proof of concept if available, and the potential impact.
For NVIDIA's security process and published bulletins, see NVIDIA Product Security.