Only the latest released version receives security fixes.
Do not open a public issue for security-sensitive reports. Contact the maintainer privately with:
- A concise description of the issue.
- Reproduction steps.
- Affected server software and versions.
- Relevant configuration snippets with secrets removed.
The maintainer will confirm receipt, investigate, and publish a fix or advisory when appropriate.