Looking back at the report this is all using HTTP endpoints not HTTPS. That makes me wonder if there's a (transparent) HTTP proxy in the circuit. It used to be a common issue with ISPs operating them and altering response bodies.
I'd recommend testing with HTTPS URLs. I use HTTP and have never experienced this and we don't have other similar reports so it is unlikely to be a general Debian infrastructure issue.

