The security promise of this project is the linear-time guarantee: no pattern, on any input, should be able to force super-linear matching. If you've found one that does — or anything else with security impact — please report it privately instead of opening a public issue.
Use GitHub's private advisory form: Report a vulnerability
A minimal pattern and input that reproduces the blow-up is the most useful thing you can send. I'll acknowledge within a few days and keep you posted on a fix, and I'm glad to credit you on release unless you'd rather stay anonymous.
Supported versions: the latest tagged release.