Security fixes are applied to the current release line. Users should reproduce an issue with the latest release before reporting it when that is safe to do.
Do not open a public issue for a vulnerability.
Use GitHub private vulnerability reporting. Include the affected version, impact, reproduction steps, relevant client and proxy versions, and any proposed mitigation. Remove credentials, private addresses, player data, and unrelated logs.
The maintainer will acknowledge the report, investigate it, and coordinate disclosure. Timelines depend on severity, reproducibility, and protocol compatibility. Please allow time for a fix and release before publishing details.
Security reports may cover packet handling, inventory transaction behavior, dependency risks, permission bypasses, denial of service, unsafe deserialization, and unintended data exposure. Ordinary bugs and feature requests belong in the issue tracker.