Vulnerabilities must be reported using the project's security advisory. All vulnerability reports MUST be submitted through the channel listed above. This allows the maintainers to assess the report, ...