Skip to content

Security: MethodWhite/Noctua-C

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Noctua-C, please report it privately.

Do not open a public issue for security vulnerabilities.

How to report

  1. Email: methodwhite@proton.me
  2. Or open a GitHub Security Advisory

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: within 48 hours
  • Initial assessment: within 5 business days
  • Fix timeline: depends on severity

Scope

  • Buffer overflows in loaders
  • Memory safety in modules
  • Unsafe deserialization of binary formats
  • Any crash triggered by crafted input

There aren't any published security advisories