Backported CVE fixes

  • Fix for - CVE-2020-7071 - PHP will accept an URL with invalid password as valid URL