Security fixes are prioritized for the latest stable release line. Older versions may receive fixes on a best-effort basis.
Do not open a public issue for security vulnerabilities. Use one of these private channels:
- GitHub Security Advisory: use the repository's Security tab
- HauntedMC support: https://www.hauntedmc.nl/support
Include affected versions, reproduction steps or proof of concept, impact, and any proposed mitigation. Do not include production credentials or unrelated private data.
For HauntedObservability, security reports are especially relevant when telemetry could expose credentials, player identifiers, SQL/query text, Redis keys/payloads, private network details, or allow untrusted data to create unbounded telemetry cardinality.
Please allow maintainers time to validate and patch an issue before public disclosure. We coordinate disclosure after a fix or mitigation is available.