This has been fixed upstream in 7.65.0: https://curl.haxx.se/docs/CVE-2019-5436.html. We will need to update curl to the latest version.