If you discover a security vulnerability in Noctua-C, please report it privately.
Do not open a public issue for security vulnerabilities.
- Email: methodwhite@proton.me
- Or open a GitHub Security Advisory
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgment: within 48 hours
- Initial assessment: within 5 business days
- Fix timeline: depends on severity
- Buffer overflows in loaders
- Memory safety in modules
- Unsafe deserialization of binary formats
- Any crash triggered by crafted input