Please do not report security vulnerabilities through public GitHub issues.
Use GitHub's private vulnerability reporting instead. This keeps the details confidential until a fix is ready.
If you prefer email, send a report to geojson@konfirm.eu with the subject line [geojson] Security vulnerability.
- A description of the vulnerability and its potential impact
- The affected version(s)
- Steps to reproduce or a minimal proof-of-concept
- Any suggested mitigations, if you have them
- Acknowledgement within 72 hours
- A fix or mitigation plan within 14 days for confirmed issues, depending on severity and complexity
- Credit in the release notes unless you prefer to stay anonymous
Only the latest release receives security fixes. If you are on an older version, upgrade first before reporting — the issue may already be resolved.
This project follows coordinated disclosure: details are kept private until a patch is published, after which the advisory is made public.