Please do not open a public issue for security problems.
Report it privately from the Security tab of the repo the problem is in, using Report a vulnerability. This creates a GitHub security advisory that only you and the maintainers can see.
Include what is affected, the version you tested, and steps to reproduce it if you can.
I review every report and reply in the advisory. Once a fix is ready, it ships in the next release and the advisory is published after that version is out. You are credited in the advisory unless you ask not to be.
Only the latest release gets security fixes.