This page publicly credits security researchers who reported a vulnerability on this site under responsible disclosure.
How to report
The full procedure (contact, PGP key, remediation timeline) lives in security.txt (RFC 9116) — that’s the single source of truth. Please report any vulnerability responsibly, without exploiting it beyond what is strictly necessary to demonstrate it. Reports can remain anonymous on request.
Researchers
No report has been credited here yet. If you found a vulnerability that was fixed on this site and would like to be listed, please let us know when you report it.
(Each future entry will list: date, name or handle, vulnerability class — no exploitation detail — and an optional link, only with the reporter’s consent.)