Security fixes are applied on the latest code in the default branch.
Do not post sensitive exploit details in a public issue.
If your hosting platform supports private vulnerability reporting, use that first. Otherwise, open a minimal public issue requesting a private contact channel and share only high-level impact details until maintainers respond.
Examples of high-priority reports:
- Bypass of rule controls leading to unintended forwarding
- Exposure of secrets/tokens in logs or storage
- Remote code execution or unsafe deserialization
- Permission misuse causing data exfiltration