The current release line (1.x) receives security fixes. Older major versions are not supported.
Please do not report security vulnerabilities through public GitHub issues.
Use GitHub's private vulnerability reporting instead. Go to the Security tab of the repository and select "Report a vulnerability" to open a private Security Advisory. This keeps the details confidential until a fix is available.
Include as much detail as you can: a description of the vulnerability, steps to reproduce, affected versions, and any relevant logs or screenshots. Maintainers will acknowledge the report and work with you on a fix and disclosure timeline.