Don't report any security issue publicly here!
What if you find any security problem with Play framework?
All security bugs in Play should be reported by email to
security@playframework.com
We strongly encourage folks to report such problems to our private
security mailing list first, before disclosing them in a public forum.
This list is delivered to a subset of the core team who handle security issues.
You can also see a summary of security vulnerabilities at
https://playframework.com/