this fixes many high-severity CVEs (cherry picked from commit b2f46b6e80c80953a64927bb9333cdef94ccbffe)