From 3610afd52bd51b52d1f70bb210e903f9faf21302 Mon Sep 17 00:00:00 2001 From: Koichiro Iwao Date: Fri, 17 Apr 2026 21:10:26 +0900 Subject: [PATCH] Clarify handling of duplicate vulnerability reports --- SECURITY.md | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/SECURITY.md b/SECURITY.md index 88713875..53639fd1 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -10,3 +10,8 @@ If you have anything else you want to report privately to developers, send us an * [xrdp-core@googlegroups.com](mailto:xrdp-core@googlegroups.com) +## Handling of Duplicate Reports + +Due to the high volume of vulnerability reports we receive, duplicate reports are handled on a first-come-first-served basis, even if discovered independently by different parties. Consequently, only the first reporter will be acknowledged in the public advisory. + +As reports remain confidential until public disclosure, reporters may not know if they are the first to submit. We appreciate your understanding.