Security fixes are developed against the latest release and the default branch. Users should upgrade to the latest available release before reporting an issue.
Do not disclose exploitable details in a public issue. Use Report a vulnerability on the repository's Security tab to send a private report. If private vulnerability reporting is unavailable, contact the maintainer through their GitHub profile and request a private channel without including the vulnerability details.
Include the affected version, deployment model, reproduction conditions, impact, and any tested mitigation. Reports concerning BIRD control-socket framing should also identify the BIRD version and approximate reply size.