Security fixes are supported on the current main branch and should be included in the next release after validation.
Please avoid filing a public issue for a vulnerability that could expose credentials, local files, command execution, VPN traffic, or other sensitive user data.
Use GitHub's private vulnerability-reporting flow from the repository's Security tab when it is available. If private reporting is not enabled, contact the repository owner through GitHub before sharing exploit details publicly.
Include the affected version or commit, the relevant platform, reproduction steps, expected impact, and any mitigation you have already tested. Remove real credentials, tokens, VPN profiles, and unrelated private data from logs or examples.
For ordinary bugs that do not require confidential handling, use the public issue tracker.