- HTTP/2 security updates: streams reset on header size violations, cookies count toward header limits, and nghttp2 CVE‑2026‑27135 patch applied.
- OAuth2 fixes: mitigated a timing side‑channel in HMAC verification and resolved a crash in AES‑CBC token cookie decryption.
- Minor bugfixes/behavior changes: fixed a crash in dynamic module filter construction, hid upstream transport failure reason from response bodies, and made load‑balancer rebuild coalescing opt‑in.