- Fix CVE‑2025‑64527: Envoy crash when JWT authentication uses remote JWKS fetching.
- Fix CVE‑2025‑66220: Correct TLS certificate matcher handling of embedded null bytes in subjectAltName.
- Fix CVE‑2025‑64763: Resolve potential request‑smuggling via early data after CONNECT upgrade.