Hi,
See https://www.apache.org/security/. You can also send a mail directly
to the project's security liust: [email protected]
Uwe
Am 10.07.2026 um 15:00 schrieb Aditya:
Hi Team,
I'm an independent cybersecurity professional and recently identified
a security vulnerability impacting one of your online platforms.
Could you let me know the correct channel for responsible disclosure?
A security contact email, bug bounty page, or disclosure policy would
be ideal.
Thanks,
Aditya
Cybersecurity Researcher
--
Uwe Schindler
Achterdiek 19, D-28357 Bremen
https://www.thetaphi.de
eMail:[email protected]