The version of Monolog used has a security vulnerability: Seldaek/monolog#448. The solution seems to be to upgrade to ~1.16.0.
The version of zend-http used has a security vulnerability: http://framework.zend.com/security/advisory/ZF2015-04. The solution to this is to upgrade to ~2.4.1.