Do not disclose a vulnerability in an issue or attach a sensitive PDF to one. Use the repository's Security > Report a vulnerability flow so the owner can investigate through a private Security Advisory.
Include the affected CocoaPDF version, operating system and architecture, the smallest safe reproduction, security impact, and any suggested mitigation. You may omit or redact source documents when disclosure would expose confidential data.
Only the latest GitHub release is supported with security fixes while CocoaPDF is pre-1.0. Please allow time for acknowledgement and coordinated remediation before public disclosure.