- Fix AzureAD OAuth client secret exposure via the /config endpoint (CVE-2026-42151).
- Reject snappy-compressed remote write/read requests when declared decoded length exceeds the limit (CVE-2026-42154).
- Patch stored XSS vulnerability in old UI heatmap chart tick labels.