Security Report

Report a vulnerability

Use this form to report a security vulnerability in COSOSO products. We aim to acknowledge reports within 72 hours.

If you have something to attach — a proof of concept, a crash dump, a packet capture, a patch — the form cannot take it. Email security@cososo.co.uk instead. For anything you need encrypted in transit, use GitHub private vulnerability reporting; we do not currently publish a PGP key.

Full coordination process and policy: GitHub SECURITY.md.