Fix for CVE-2019-16782: Prevent timing attacks targeted at session ID lookup.
Diff: https://github.com/rack/rack/compare/2.0.7..2.0.8