Report vulnerabilities privately to support@freshost.net with the subject
pve-snapshot-api security report. Include the affected release, impact and
redacted reproduction steps. Do not post credentials or exploit details in issues.
Security fixes target the latest release; older versions have no separate backports. We coordinate fixes and disclosure with reporters.