Please use GitHub security advisiories to report vulnerabilities.
Warning: Please, do not use regular public issues!
This project is maintained by volunteers, with a single developer doing most of the work. As such, please give us no less than 60 days to work on a fix before public exposure. Also, please have a look at our no warranty statement and the software life cycle policy.