Please report suspected vulnerabilities privately through GitHub's security advisory form. Do not open a public issue for an unpatched vulnerability.
Reports are reviewed as maintainer time allows. Include the affected version, reproduction steps, and any proof of impact.