- - Security updates: CVE‑2024‑25629 c‑ares out‑of‑bounds read fix; RFC1918 addresses no longer treated as internal; added P‑384/P‑521 curves, improved SNI/SAN validation, and Signed Double Submit Cookie pattern.
- - New defaults and features: shadow requests streamed in parallel, local replies traverse filter chain after 1xx headers, JSON access‑log formatter enabled by default, DNS nameserver rotation with retries, UDP‑GRO for QUIC, and OAuth2 re...
- - Wasm and tracing changes: removed deprecated Opencensus extension, adjusted route‑cache behavior for newer ABI, added Wasm VM reload support and Go plugins.