[Security Follow-up] Request for status update on private report submitted on August 2, 2026
Check Ahead
I have searched the issues of this repository and believe that this is not a duplicate.
I am willing to try to fix this bug myself.
Ⅰ. Issue Description
Hello Seata team,
I am writing to respectfully follow up on a private security report that I submitted to the Apache Security Team on August 2, 2026.
Timeline:
- August 2, 2026: Initial private report submitted to [email protected], with [email protected] copied.
- August 31, 2026: Follow-up sent to the Apache Security Team.
- August 31, 2026: A Seata maintainer confirmed that the report had been received and would be coordinated with the PMC.
- September 6, 2026: Follow-up request sent.
- September 9, 2026: Additional follow-up request sent.
- September 14, 2026: I have not yet received a further status update or tracking information.
For reference, I previously opened a status follow-up in #8213: https://github.com/apache/incubator-seata/issues/8213
I understand that security-related matters may require private handling and coordination. I have followed the ASF responsible-disclosure process and will continue to respect the project’s preferred procedures.
Could you please confirm whether the report is being handled by the appropriate team, and let me know whether any further information or assistance is needed from me?
This report is part of my ongoing research. If you have any questions, please feel free to @mention me at any time. I would be very happy to provide assistance and contribute to improving Seata’s security.
Thank you for your time and assistance.
Best regards,
Ⅱ. Describe what happened
No response
Ⅲ. Describe what you expected to happen
No response
Ⅳ. How to reproduce it (as minimally and precisely as possible)
No response
Ⅴ. Anything else we need to know?
No response
Ⅵ. Environment
No response
Source: apache/incubator-seata