- Security fixes for CVE-2026-26330, CVE-2026-26308, CVE-2026-26310, CVE-2026-26309, and CVE-2026-26311, addressing ratelimit crashes, RBAC header bypass, IPv6 address handling, JSON off‑by‑one write, and blocked HTTP decode after downstre...
- Bug fix: OAuth2 refresh requests now preserve the original Host header instead of being overwritten by host rewriting.
- Dependency updates: migrated googleurl source to GitHub, upgraded Kafka test binary to 3.9.2, and refreshed Docker base images.