The vulnerabilities depend on different permissions and configurations, but supported sites should still install the appropriate security release. Maintainers of contributed modules that handle HTMX attributes or implement custom stream wrappers should review the accompanying hardening.
...more