Upgrade to the 2.7.x branch needs some work (see #288574), let's patch the security issue in the meantime.