February 7th, Thirty fifth public release 1.1.6, 1.2.8, 1.3.10 * Fix CVE-2013-0263, timing attack against Rack::Session::Cookie