- Fix CVE‑2026‑48020 (GHSA‑xf64‑8mw2‑4gr2).
- Fix bugs in TLS options computation, basic‑auth validation, ingress path matcher injection, request path normalization, and routing context handling.
- Update golang.org/x/net to v0.55.0 and golang.org/x/crypto to v0.52.0.