This qualification isn't really accurate:

> The change for #16611 reintroduces "lax" parsing behavior that the security fix [1] was supposed to prevent

since the #16611 changes were committed *before* the security fix.
