If you discover a security vulnerability in the AIR v1 specification or reference tooling, please report it responsibly.
Do NOT open a public GitHub issue for security vulnerabilities.
Instead, please use one of these channels:
- GitHub Security Advisories (preferred): Report a vulnerability
- Email: contact@cyntrisec.com
- Description of the vulnerability
- Steps to reproduce
- Potential impact assessment
- Suggested fix (if any)
- Acknowledgment: Within 48 hours
- Assessment: Within 7 days
- Fix: Depends on severity; critical issues prioritized
- COSE/CWT receipt structure (signature bypass, claim parsing, malformed vectors)
- Golden vector correctness (test vectors that incorrectly pass or fail)
- Verification algorithm (logic errors in the normative verification steps)
- Interop tooling (Python/JS reference verifiers)
| Version | Supported |
|---|---|
| v1.0.x | Yes |