Confidential Security Report: DoS in TagLib ASF (.wma) handling

Urs Fleisch urs.fleisch at gmail.com
Fri Sep 11 17:18:30 BST 2026


> Sure, I'll check it out. I have a question, are CVE ID requests handled through GitHub?

For a past incident, someone told me that "for CVE assignment,
GitHub's Security Advisory system (Settings → Security → Advisories)
can assign a CVE ID directly". In the "Settings" tab of the project, I
see only "You don't have access to repository options", so I cannot
use this. Maybe someone with more privileges can step in.


More information about the taglib-devel mailing list