> I assume this behavior is related to CVE-2025-41242 [1] as it > does not seem to occur with 5.1.4. That change only affects tickets relayed with POST, which I don't think is common. I would expect literally no difference the traces otherwise. The risky change is in 5.2 to get off a Spring class building the URLs and it hasn't shipped yet. -- Scott