I take the security of MyDNS seriously. If you discover a security vulnerability within this project, please do not open a public issue. Instead, follow the process below to report it privately.
Please report all security vulnerabilities via GitHub Private Vulnerability Reporting. This allows for a secure, private communication channel between you and the maintainer (Aaron Fredrick).
You can submit a report by going to the Security tab of this repository and selecting Vulnerability reporting -> Report a vulnerability.
- I will acknowledge your report within 48 to 72 hours.
- I will perform a preliminary analysis and keep you informed of the progress.
- Once the vulnerability is confirmed and a fix is prepared, I will coordinate a disclosure date with you.
This policy applies to:
- The core DNS server logic.
- The web management dashboard.
- Default configurations provided in the repository.
Please do not use this process for:
- General bug reports (use Issues).
- Feature requests.
- Help with configuration.
Thank you for helping keep MyDNS secure!