No secrets in advisories
Do not publish real user data, production logs, URL fragments, object keys, signed URLs, provider payloads, or sensitive report material.
Advisories
PrivShare publishes security advisories when a vulnerability is confirmed, remediated, and ready for responsible public disclosure.
This initial archive is intentionally empty until an advisory is published.
This is not a claim that PrivShare has never had or will never have a security issue. Future confirmed advisories should be published here with impact, status, remediation, and credit where permission is given.
The archive should make security work visible without exposing users or researchers.
Do not publish real user data, production logs, URL fragments, object keys, signed URLs, provider payloads, or sensitive report material.
Researchers are credited only if they explicitly permit public acknowledgement.
Use this structure for future public security advisories.
PSA-YYYY-NNN: Short title
Date published:
Date fixed:
Affected versions:
Severity:
Status:
Impact:
What happened:
What changed:
What users should do:
Credit:
References:Keep reading
Every security page links to the others so you can move through the full model without using the browser back button.