CVE-2026-25886 has been dropped as we've deemed it not exploitable without prior attacker control, and we will be adding features in the future to make the corresponding behavior configurable.
Releases 2025.8.6, 2025.10.4 and 2025.12.4 with fixes included are available here: