- Patched CVE-2025-64527 preventing Envoy crashes when JWT authentication uses remote JWKS fetching.
- Resolved CVE-2025-66220 TLS certificate matcher issue with embedded null bytes in SANs.
- Mitigated CVE-2025-64763 potential request smuggling via early data after CONNECT upgrade.