Report a vulnerability
Use this form to report a security vulnerability in COSOSO products. We aim to acknowledge reports within 72 hours.
If you have something to attach — a proof of concept, a crash dump, a packet capture, a patch — the form cannot take it. Email security@cososo.co.uk instead. For anything you need encrypted in transit, use GitHub private vulnerability reporting; we do not currently publish a PGP key.
Full coordination process and policy: GitHub SECURITY.md.