Please do not open a public GitHub issue for a suspected security vulnerability.
Use GitHub private vulnerability reporting when available. Otherwise contact the maintainer privately through a channel published on the maintainer's GitHub profile.
Useful reports include reproducible detail about bootstrap/download integrity, patch provenance, command execution, path/config isolation, build/runtime packaging, or accidental credential disclosure. Do not include unrelated secrets or personal data.
Security fixes target the current main branch and the currently documented native-Windows support baseline. Upstream vLLM vulnerabilities that are not introduced or changed by this Windows patch/distribution layer should also be reported to the appropriate upstream project.