Please do not report security vulnerabilities through public GitHub Issues.
Use GitHub Private Vulnerability Reporting or a private Security Advisory for this repository if that feature is enabled. If it is unavailable, avoid publishing exploit details publicly and use the repository owner's private contact options on GitHub. This repository does not currently publish a dedicated security email address.
Security reports may include issues such as credential or header leakage, path traversal, unsafe file writes, arbitrary file access, TLS or network-security failures, sensitive-data exposure, or vulnerabilities in upload and download handling.
Please include:
- The affected NativePHP Fetch version
- Platform and OS version
- NativePHP Mobile version
- Reproduction information or a minimal proof of concept
- Security impact and realistic attack conditions
- A suggested mitigation, if known
Please remove unrelated credentials, tokens, personal data, and private file contents from reports. We will acknowledge and investigate responsible reports as promptly as project availability allows.