*) http_protocol: Escape request method in 413 error reporting. Determined to be not generally exploitable, but a flaw in any case. PR 44014 [Victor Stinner <victor.stinner inl.fr>]
This is CVE-2007-6203. Maybe you should add the reference to the CHANGES file? Cheers, Stefan