Please do not open a public issue for security problems.
Use GitHub's private vulnerability reporting on the affected repository instead: open its Security tab, then choose Report a vulnerability. If that option is unavailable, use any private reporting channel documented by that repository and do not publish vulnerability details in an issue or discussion.
Please include reproduction steps, the affected version or commit, and relevant environment details. You will receive an acknowledgement within a few days.
Unless a repository documents a different policy, only its latest release and current default branch are supported. Security fixes land on the default branch first.