Security fixes target the current main branch.
If you find a vulnerability, avoid posting exploit details publicly. Use GitHub private vulnerability reporting if it is available for this repository. If it is not available, open an issue with a high-level description and mark it as security-sensitive so maintainers can move the discussion to a private channel.
Please include:
- affected command, module, or data path;
- minimal reproduction steps;
- expected impact;
- any safe mitigation you already tested.