Only the latest release on the default branch receives security fixes during the Beta.
Please do not open a public issue for token disclosure, authorization bypass, stored content injection or rate-limit bypass.
Use GitHub's private vulnerability reporting for this repository. Include:
- affected version or commit;
- reproduction steps;
- expected and actual behavior;
- potential impact;
- any suggested mitigation.
We aim to acknowledge reports within seven days. Avoid accessing screens or data that you do not own.
Self-hosters should keep Wrangler and project dependencies updated, apply all database migrations, use HTTPS, and review their Cloudflare access and logging settings.