Void ships a rootless, read-only container and extra security headers. Report Void-specific issues to the instance maintainer. Upstream SearXNG issues still go to security@searxng.org.
We love responsible reports of (potential) security issues in SearXNG.
You can contact us at security@searxng.org.
Be sure to provide as much information as possible and if found also reproduction steps of the identified vulnerability. Also add the specific URL of the project as well as code you found the issue in to your report.