If you have discovered a security issue, please report it privately through GitHub Security Advisories. Please refrain from creating a public GitHub issue or disclosing the vulnerability publicly. We prefer a Coordinated Vulnerability Disclosure (CVD) to properly understand and fix the root cause problem.
The advisory form guides you through the required details, so please describe the issue.
A member of the security team will confirm the vulnerability, determine its impact, and develop a fix. The fix will be applied to the master branch, tested, and packaged in the next security release.
Thanks in advance for your support to make our products safer!