Until the first stable release, only the latest release candidate on the default branch receives security fixes.
Use GitHub's private vulnerability reporting for this repository. Include the affected version and platform, a minimal reproduction, the expected impact, and whether the issue is already being exploited.
Do not open a public issue and do not include live credentials, private keys, server addresses, or user traffic. You should receive an acknowledgement within seven days. A fix and disclosure timeline will be coordinated after the report is reproduced.
Protocol compatibility bugs without a security impact may be reported through the public issue tracker after removing sensitive configuration and traffic.