A security review of one of the MediaWiki installation's I help manage has flagged lua as being vulnerable to CVE-2014-5461 and CVE-2021-43519. While it looks like CVE-2014-5461 has been patched, there is no indication of this in the version number and it isn't clear that CVE-2021-43519 has been addressed at all.
The patches for these binaries should be provided in version control somewhere (I can't find that linked on T72541) and the version numbers should be updated to indicate that wmf has patched them. Kind of like Debian's -bpo indications.