Title: a security issue in jython
Created on 2016-04-13.02:32:47 by redrain, last changed 2018-02-25.09:02:25 by jeff.allen.

i found a vulnerability about deserialization , but i didn't find any security issue reporting email address.
i want to know the best way to report this vunerability, create a open issue or email?
Deserialization is the execution of arbitrary code from the source. Are we talking about pickle here or Java serialization? Anything not covered by:

Adding the PM as nosy.
