- Patched CVE‑2026‑54761 and CVE‑2026‑54762 (GHSA advisories).
- Fixed several k8s ingress/nginx, gatewayapi, and TLS router bugs (auth secret handling, endpointslice fencing, cross‑provider refs, host/TLS option conflicts, snicheck).
- Bumped go‑proxyproto dependency to v0.12.0.