This is a security fix; disclosure to follow shortly. Thanks Sam Cooke for the report and draft patch.