Please use GitHub's private vulnerability reporting feature when it is enabled for the affected repository. If private reporting is unavailable, open a minimal issue asking for a private contact channel without including exploit details, credentials, personal data, or other sensitive information.
Include the affected component and version, impact, reproduction conditions, and any suggested mitigation. Reports will be acknowledged and assessed as time permits; no response-time or remediation-time guarantee is made.
Only the latest revision of actively maintained projects is generally eligible for security fixes.