Please report security issues privately, not through a public issue or pull request.
The preferred channel is GitHub's private vulnerability reporting. Go to the Security tab of this repository and click Report a vulnerability. That keeps the report, the proof-of-concept, and the discussion private while a fix is prepared, and it lets us open a draft advisory and coordinate a CVE from the same place.
Please paste the details or link them rather than sending archive attachments.
When you report, include what you have: the affected version, a description of the issue, and a self-contained way to reproduce it. We will confirm the problem, work on a fix, and coordinate the release. We are happy to credit you in the advisory and the changelog if you would like that.
Security fixes target the latest release line. Please make sure you can reproduce the issue on the most recent release before reporting.