Sobering thought for me is how probable it is that a similar issue might be present in other platforms. The title calls it "rare" but given (a) the number of complex-enough web/app platforms in use today, (b) just the endless number of ways/infra permutations for "doing x", and (c) the size of a typical company's codebase and dependencies, could it be a more common occurrence than we think?
Total anecdote, up for you to believe: Back in April 2016, one of my then-housemates bought a brand-new Macbook Air. A week into his ownership, he exclaims surprise that he is logged-in to another Facebook account, someone we are totally not acquainted with. I borrow his MBA and try to investigate but, alas, I lack expertise for it. The only relevant thing I can eke out is that they both went to the same event a week or so ago and probably shared a Wifi AP, where a "leak" could've happened. Or maybe a hash collision in FB's side?
I would've reported it to FB but then I don't have enough details; with the two conjectures I have, I'm basically holding water with a sieve. But now the thought that someone I totally don't know might end up logged-in in my FB account is a possibility that bothers me. And I have no idea how to prevent it other than minimizing what could be compromised (and no, "Get off FB!" just isn't in the cards, I'm sorry).
Kudos for Github for investigating and fixing this issue. Another thought that occurred to me while writing this is how many users of other platforms might be filing issues like this but can't provide enough detail and so their reports are eventually marked as "Could Not Reproduce". Not exactly leaky sessions but just general security mishaps that they would struggle to describe to support.