Security Policy

Supported versions

Security fixes are made against the latest released version of Alien::nghttp3.

Reporting a vulnerability

Please do not open a public GitHub issue for a suspected vulnerability.

Report security issues privately using either:

Please include enough information to reproduce and understand the issue.

If the problem is ultimately in upstream nghttp3 rather than Alien::nghttp3, it may be referred to the nghttp3 project after the issue has been evaluated.