Please report vulnerabilities privately through GitHub's Report a vulnerability flow in the repository Security tab. Do not open a public issue until a fix is available.
Include affected versions, a minimal reproducer or capture when possible, impact, and any suggested mitigation. Reports involving parser panics, unbounded memory growth, deadlocks, unsafe bus writes, or device-identity spoofing are in scope.
Security fixes target the latest released minor version. Older v0 minor
lines may require upgrading because the public API is still pre-1.0.