- HTTP/2 streams now reset when exceeding max header list size and cookies count toward header limits, mitigating HPACK cookie bomb attacks.
- OAuth2 fixes: eliminated a timing side‑channel in HMAC verification and resolved an AES‑CBC decryption crash on secret mismatch.
- Fixed a shutdown race in load‑report ADS streams; updated Docker images and documentation.