fixes CVE-2021-21705 and CVE-2021-21704 not cherry-picked from master, because that does not have php73 anymore