Bump to 1.8.6

Bump to 1.8.6 is needed due to CVE-2020-28053, reported at #975584.

Merge request reports

Loading