- Fixed CVE‑2025‑64527 causing Envoy crashes when JWT authentication uses remote JWKS fetching.
- Patched CVE‑2025‑66220 where TLS certificate matcher could mishandle certificates with embedded null bytes.
- Mitigated CVE‑2025‑64763 request smuggling via early data after a CONNECT upgrade.