* #3348: [Security:HIGH][CVE-2025-31510] XSS/HTML Injection through tab parameter when using "Choice" authentication module
* #3349: OIDC: Incorrect implementation of client_secret_basic