So they had a security-critical header whose fields are set by their internal authentication service.
And that same field can also contain arbitrary strings passed by the end user with git push -o
I know it's easy to say after the fact but still, wtf