Security fixes are applied to the latest released version.
Do not open a public issue for a suspected vulnerability. Use GitHub's private vulnerability reporting feature on the repository's Security tab. Include affected versions, reproduction steps, impact, and any suggested mitigation. Maintainers should acknowledge a report within seven days and coordinate disclosure after a fix is available.