Please report security issues privately by opening a draft security advisory or contacting the maintainers through the repository security channel.
Do not disclose vulnerabilities publicly before maintainers have had reasonable time to investigate and publish a fix.
Security-sensitive areas include cache invalidation tokens, request handling, dependency updates, Docker images and any behavior that may expose upstream HTML, cookies, headers or stack traces.