- Reset HTTP/2 streams that exceed max header list size and count uncompressed cookies toward header limits, mitigating HPACK cookie bomb and applying CVE‑2026‑47774 and CVE‑2026‑27135 patches.
- Fixed OAuth2 timing side channel in HMAC verification and corrected AES‑CBC decryption crash for token cookies.
- Resolved shutdown race in ADS stream cleanup for load reporting.