Skip to content

Security: mozilla/pdf.js

.github/SECURITY.md

Security policy

Mozilla takes the security of our software seriously. If you believe you have found a security vulnerability in PDF.js, please report it to us as described below.

Reporting security vulnerabilities

Please don't report security vulnerabilities through public GitHub issues.

Where to report depends on what's affected:

The PDF.js library or the Firefox PDF Viewer

Report the vulnerability in Bugzilla and make sure that the checkbox in the "Security" section is checked so the required access controls are automatically configured:

Security checkbox

The Mozilla security team will process the bug as described in Mozilla's security bugs policy.

The PDF.js Chrome extension

The Chrome extension isn't part of Firefox and isn't tracked in Bugzilla. Report the vulnerability privately on GitHub, using the "Report a vulnerability" form.

Learn more about advisories related to mozilla/pdf.js in the GitHub Advisory Database