- Fixes critical TLS security issues: client‑auth bypass, On‑Demand TLS directory traversal, and disables client auth when using QUIC.
- Bug fixes include Caddyfile parser robustness (fuzzed), ACME certificate acquisition errors, and a bug that prevented this version from obtaining any certificates.
- Adds new features: third‑party “supervisor” plugin, QUIC proxy improvements, configurable upstream timeout, rewrite regex support, and TLS strict host‑matching with per‑hostname client‑auth pools.