The Kestrel bug bounty program is now public
Jonas Vehko · · 1 min read
After two years as an invite-only program, anyone can now report vulnerabilities in Kestrel and our open source frameworks.
After two years as an invite-only program, anyone can now report vulnerabilities in Kestrel and our open source frameworks.
A remote code execution bug in an upstream image decoder was reachable through image optimization. Here's the timeline of how we fixed it with the maintainers.