# Security policy

MoonThrift parses untrusted schemas and payloads. Reports involving crashes,
resource exhaustion, invalid bounds handling, or malformed data accepted as
valid should be sent privately through GitHub's **Report a vulnerability**
feature for this repository.

Please include the affected version, smallest reproducer, backend, and impact.
Maintainers will acknowledge a report within seven days. Public issues are
appropriate for ordinary correctness bugs that do not expose users to harm.
