If you suspect you have found a security vulnerability, open a report using the repository's Security tab. Please include a clear and concise description of what the vulnerability is, where it is exposed in the code, and (if known) what best practices might apply to patching it.
If the issue is confirmed, a patch will be released as soon as possible.