Please report security issues privately through GitHub's private vulnerability reporting: open the Security tab of this repository and use "Report a vulnerability". Don't open a public issue or pull request for something you believe is a security problem.
You'll get an acknowledgement within a week. If the report is accepted we'll work on a fix, publish a GitHub Security Advisory with credit to you, and release a fixed gem to RubyGems.
Only the latest release on the 2.x line receives security fixes.