This bug has been fixed in the code repo, but the bugfix (along with one for a DoS vulnerability CVE-2016-10369) hasn't been released since last year. I am going to ask them for a release since I actually have no control on the package releases.