Upstream has issued an advisory on April 19: http://openwall.com/lists/oss-security/2018/04/18/2 We're not affected because our spec contains --disable-esi, but I wanted to file this to note that, and to also note that it affects all but the latest 4.0.x.
Closing.
Status: NEW => RESOLVEDResolution: (none) => INVALID