FILTERVALIDATEURL accepts URLs with invalid userinfo (CVE-2020-7071). streamgetcontents() fails with maxlength=-1 or default.
See upstream releasenotes for other changes.
{ "section": "core" }