Do not open a public issue for a vulnerability.
Use GitHub's private vulnerability reporting for this repository if available. If private reporting is unavailable, open a public issue asking for a private contact path without including exploit details.
Please include:
- Affected version or commit
- Reproduction steps
- Expected impact
- Any known mitigations
Supported surfaces include the daemon HTTP APIs, local Unix socket control path, API key handling, cluster enrollment, mTLS agent transport, and packaged deployment artifacts.