We support the most recent minor release.
See https://www.pomerium.com/docs/releases.
See https://www.pomerium.com/docs/internals/security#reporting-a-security-bug for how to report a vulnerability.
AI-assisted security reports are welcome when they include enough detail for us to reproduce the issue and assess impact.
Please disclose any AI tools used and distinguish between tool-generated analysis and behavior you personally verified. Reports that are speculative, lack a working proof of concept, or contain generic remediation text without project-specific evidence may be closed without further triage.