|
| 1 | +name: Vulnerability report |
| 2 | +description: Privately report a potential security vulnerability in CPython |
| 3 | +body: |
| 4 | + - type: markdown |
| 5 | + attributes: |
| 6 | + value: | |
| 7 | + > [!IMPORTANT] Not all bugs are vulnerabilities. Read the [Python security |
| 8 | + > policy](https://devguide.python.org/security/policy/) |
| 9 | + > before submitting, and evaluate your report against [what types of |
| 10 | + > bugs are vulnerabilities](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities) |
| 11 | + > and [what versions of Python accept reports](https://devguide.python.org/security/policy/#what-versions-of-python-accept-reports). |
| 12 | +
|
| 13 | + Python Security Response Team (*PSRT*) members balance this work against |
| 14 | + many other responsibilities. Keep the report short and in plain text: |
| 15 | + no headers, tables, PDFs, binaries, or severity and CVSS information. |
| 16 | +
|
| 17 | + Reports that do not contain a potential security vulnerability will be |
| 18 | + discarded without a reply. |
| 19 | +
|
| 20 | + This form is for CPython only. For other projects (such as pip or |
| 21 | + python.org), or if you are not sure where to send your report, email |
| 22 | + [security@python.org](mailto:security@python.org). |
| 23 | + - type: textarea |
| 24 | + id: summary |
| 25 | + attributes: |
| 26 | + label: Summary |
| 27 | + description: A few sentences describing the vulnerability. |
| 28 | + validations: |
| 29 | + required: true |
| 30 | + - type: textarea |
| 31 | + id: threat_model |
| 32 | + attributes: |
| 33 | + label: Threat model |
| 34 | + description: > |
| 35 | + What does the attacker control, and what do they gain? |
| 36 | + Describe the code, configuration, or deployment that may exist in the real world and is exploitable. |
| 37 | + Where possible, cite the relevant part of the |
| 38 | + [security policy](https://devguide.python.org/security/policy/#what-types-of-bugs-are-vulnerabilities). |
| 39 | + validations: |
| 40 | + required: true |
| 41 | + - type: textarea |
| 42 | + id: proof_of_concept |
| 43 | + attributes: |
| 44 | + label: Proof of concept |
| 45 | + description: > |
| 46 | + A script that reproduces the issue and clearly indicates whether the vulnerability is present, |
| 47 | + such as exiting with `1` if vulnerable and `0` if not. |
| 48 | + If it depends on a specially constructed binary file, include a script to construct the file rather than the file itself. |
| 49 | + Wrap scripts longer than a few lines in a |
| 50 | + [collapsed section](https://docs.github.com/en/get-started/writing-on-github/working-with-advanced-formatting/organizing-information-with-collapsed-sections) |
| 51 | + using `<details> ... </details>`. |
| 52 | + validations: |
| 53 | + required: true |
| 54 | + - type: input |
| 55 | + id: versions |
| 56 | + attributes: |
| 57 | + label: Python versions tested |
| 58 | + description: > |
| 59 | + List every version tested and indicate which were found to be vulnerable. |
| 60 | + Only [supported versions](https://devguide.python.org/versions/) accept reports. |
| 61 | + validations: |
| 62 | + required: true |
| 63 | + - type: textarea |
| 64 | + id: patch |
| 65 | + attributes: |
| 66 | + label: Suggested fix |
| 67 | + description: Ideally, a minimal patch with the mitigation. |
| 68 | + validations: |
| 69 | + required: false |
| 70 | + - type: checkboxes |
| 71 | + id: checklist |
| 72 | + attributes: |
| 73 | + label: Before submitting |
| 74 | + options: |
| 75 | + - label: I have read the security policy and evaluated this report against it. |
| 76 | + required: true |
| 77 | + - label: I have checked that this issue is not already resolved on the `main` branch. |
| 78 | + required: true |
| 79 | + - label: I have verified the factual validity of everything in this report, including any content produced by an LLM. |
| 80 | + required: true |
0 commit comments