- Fixed critical security issues: blocked LD_PRELOAD env injection in SFTP, prevented IP spoofing via PROXY protocol headers, and patched third‑party OpenTelemetry DoS vulnerability.
- Improved stability and correctness across many components (UI console tab width, X11 listener permissions, access‑request deny rules, hardware‑key enrollment messages, Kubernetes audit events, tsh command handling, installer script, etc.).
- Added operational enhancements such as Teleport Operator connection caching, PostgreSQL audit‑log binary encoding, and GCP KMS key cleanup.