Security fixes are published for the latest released module version unless a release note states otherwise.
Report suspected vulnerabilities privately through GitHub security advisories for
aep-foundation/aep-java. Include the affected module and version, a minimal reproduction or
affected code path, expected impact, and whether the issue is already public.
Do not open a public issue for an active vulnerability. Protocol design discussion belongs in the
aep-specs repository.