- Security fixes address CVE‑2025‑67735 (Netty request smuggling), CVE‑2025‑66560 (Quarkus REST thread exhaustion) and CVE‑2025‑14559 (unauthorized token issuance for disabled users).
- Enhancements add debug‑level logging warnings for ISPN/JGROUPS and allow OpenAPI artifacts to be ignored when the Quarkus distribution is disabled.
- Bug fixes resolve issues in SSO login with custom attributes, Infinispan deadlocks, duplicate OIDC address claims, admin UI event details, MS SQL migration failures, clusterless caching, unmanaged attribute handling, outdated docs, organ...