Report vulnerabilities privately via GitHub Security Advisories. Acknowledgment within 2 business days; disclosure timeline within 5 business days.
- SFU session-management bugs (room cross-tenant leaks, peer-identity spoofing)
- DTLS/SRTP key-exchange issues
- TURN credential leak via the realtime token mint
- ICE candidate restriction bypass
- Gateway scope/meter integration bypass via realtime path