Until the first stable release, security fixes are applied to the latest development version only.
Please do not report security vulnerabilities in public issue trackers. Contact the maintainers privately with a description, reproduction steps, affected versions, and any suggested mitigation. The project will acknowledge receipt and coordinate disclosure.