Summary of changes:
CVE-2025-58137: auth bypass through user-controlled key
CVE-2025-58130: insufficiently protected credentials
See also:
Issues resolved: