If you discover a security vulnerability in tollbooth, please report it responsibly.
Do not open a public issue.
Instead, use GitHub's private vulnerability reporting with:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
We aim to acknowledge reports within 48 hours and provide a fix or mitigation plan within 7 days.
| Version | Supported |
|---|---|
| latest | ✓ |
Security issues in tollbooth's core middleware, challenge generation, cookie signing, rate limiting, and framework integrations are in scope. Issues in third-party dependencies should be reported to their maintainers.