]> git.ipfire.org Git - thirdparty/curl.git/commitdiff
VULN-DISCLOSURE-POLICY.md: issues that should be found by tests are LOW
authorDaniel Stenberg <daniel@haxx.se>
Fri, 26 Jun 2026 14:23:08 +0000 (16:23 +0200)
committerDaniel Stenberg <daniel@haxx.se>
Fri, 26 Jun 2026 20:46:31 +0000 (22:46 +0200)
Closes #22190

docs/VULN-DISCLOSURE-POLICY.md

index a115ee171622391146d8801ecbb959355335d092..847579edb521401a72c8ed7086f733f10fffbaee 100644 (file)
@@ -183,6 +183,10 @@ trigger. Due to timing, platform requirements or the fact that options or
 protocols involved are rare etc. [Past
 example](https://curl.se/docs/CVE-2022-43552.html)
 
+Issues that are likely to be detected by basic testing are likely to not be
+considered more severe than **Low**. Users that do not test cannot be expected
+to have secure setups to begin with.
+
 ## Medium
 
 This is a security problem that is less hard than **Low** to exploit or