Security Policy Report vulnerabilities through Elastic's security process. Do not open a public GitHub issue for a security report.