In the end we decided on *not* a #curl security issue, but it's not an easy one to make:

hackerone.com/reports/3373640

#curl