Please report a security problem through GitHub's private vulnerability reporting for this repository. Do not open a public issue with a working exploit or a capture from a real target.
Remove all authorization headers, cookies, API keys, query values, request bodies, and response bodies from any sample. The built-in doorlab is usually enough to demonstrate a replay or classification bug.
The latest tagged release receives security fixes. The project is pre-1.0, so report schema and configuration changes may occur between minor versions and will be documented in the changelog.