- Patched multiple CVE‑2026 security issues: multivalue header RBAC bypass, IPv6 address crash, JSON off‑by‑one write, and HTTP decode after downstream reset.
- Fixed OAuth2 token refresh handling so host rewriting does not override the original Host header.
- Updated dependencies: migrated googleurl to GitHub, upgraded Kafka test binary to 3.9.2, and refreshed Docker base images.