Access permissions in rpcd and uhttpd

Jo-Philipp Wich jo at mein.io
Sun Jul 19 23:23:06 PDT 2026


Hi Hauke,

> I send this mail to the public mailing list because I want such a 
> discussion. I do not think these are big problems we have to manage in 
> private and then release in a coordinated way.
 > [...]

I agree, such "low impact" report can be published right away and fixed 
on the next occasion, basically handle them like an ordinary issue report.

The disclosure / CVE request flow etc. should be reserved for high 
impact issues like unauthenticated code injection or similar.

Regards,
Jo



More information about the openwrt-devel mailing list