Report vulnerabilities privately to Ivan Zorin, creator@localzet.com. Include the PHP and Server versions, a minimal reproduction and expected behavior. Do not publish credentials, user data or exploit details in public issues before a fix is available.
Fixes are verified against the current default branch. A maintenance schedule for older release lines has not been established. A successful local test or CI run does not guarantee the security of an application deployment: validate proxy trust, TLS, protocol limits, session storage and exposed listeners for your application.