Highlights
HTTP Header Injection: 1 prior fix. Scrutinize any change in this area.
Request.php: most-fixed (1 issue). Treat as high-risk during review.
0 high-severity fixes in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
HTTP Header Injection: Inverted logic in validation checks allowed malformed cookies containing control characters to bypass security filters. This can lead to malicious headers being injected into outbound HTTP requests generated by the client, potentially enabling HTTP Request Smuggling or hijacking of target sessions.