RDC is research software and is not a security boundary. Do not process untrusted images without application-level limits on file size, dimensions, pixel count, inflated data, memory, and execution time.
Prefer GitHub's private vulnerability-reporting or Security Advisory interface for this repository. If that interface is unavailable, contact the maintainer at anar.bastanov.out@gmail.com with the subject RDC Security Report.
Include the affected commit or release, platform, reproduction steps, impact, and a minimal test file when it is safe and legal to share. Allow a reasonable embargo for analysis and a coordinated fix. Do not open a public issue that contains an exploit or a malicious sample before the report has been assessed.
Only the latest repository state and most recent tagged release are eligible for security fixes. Older prereleases may be asked to upgrade.