Do not disclose suspected vulnerabilities, credentials, host identities, or deployment details in a public issue. Use GitHub's private vulnerability reporting action on this repository. If that action is unavailable, contact a REZICS organization owner privately.
Include the affected revision, impact, reproduction conditions, and any evidence that can be shared safely. Do not probe systems you do not own or have explicit permission to test.