Please do not disclose a suspected vulnerability in a public issue or pull request. Use the repository's Security > Report a vulnerability form so certificate, proxy, capture, and parser issues can be assessed without exposing users before a fix is available.
The current main branch and latest release receive security fixes. Reports should include the
affected version, impact, reproduction steps or a proof of concept, and any suggested mitigation.
Never include real captured credentials, cookies, private keys, or traffic from third parties.