Please report a suspected vulnerability privately through GitHub Security Advisories. Do not post live keys, signed production plans, nonces, or user payloads in a public issue.
The reference library intentionally excludes transports, account sessions, arbitrary commands, and inbound listeners. Security reports that demonstrate signature, replay, time-window, digest, allowlist, or size-limit failures are especially useful.