Security fixes are provided for the latest SDK release.
Use GitHub private vulnerability reporting: open the repository's Security tab, choose Advisories, and select Report a vulnerability. Do not open a public issue for an undisclosed vulnerability.
Include the affected SDK and host versions, platform, plugin distribution mode, a minimal reproduction, and the security impact. Issues involving cross-DLL ownership, allocator mismatches, unsafe FFI, handle lifetime, or untrusted plugin loading are especially important.