- Fixed CVE‑2025‑64527: Envoy crash when JWT authentication uses remote JWKS fetching
- Patched CVE‑2025‑66220: TLS certificate matcher now correctly handles embedded null bytes in subjectAltNames
- Mitigated CVE‑2025‑64763: Prevented request smuggling from early data after CONNECT upgrade