Skip to content

Report a Vulnerability

Do not open public issues or pull requests for credential exposure, policy bypass, unsafe execution/routing, audit compromise, malicious artifacts, or exploitable failures.

ScopeChannel
OSS codehttps://github.com/Garudex-Labs/caracal/security/advisories/new
Sensitive attachments/contextsupport@caracal.run
Enterprise-only/private customer contextEmail only; outside this workspace

Include summary, version/commit, boundary, prerequisites, minimal reproduction, observed/expected, impact, and mitigation if known. Redact credentials/customer data.

Maintainers aim to respond within up to seven days; this is not a resolution SLA.

Retain identifier and sanitized copy. Continue through the same private channel.

Keep private until fix/mitigation or coordinated outcome. For active exploitation, contain with Respond to Incidents.

Review Review the Threat Model.