- Added several security fixes including path matcher backslash normalization, header underscore handling, placeholder re‑expansion prevention, and improved HTML stripping (may be breaking for dependent code).
- Fixed multiple bugs and stability issues such as client auth, TLS state races, reverse‑proxy body handling, IDN SNI matching, IPv6‑only start support, and performance improvements for replacer placeholders and content‑negotiation.
- Updated dependencies, added regression tests, and performed minor enhancements and typo clean‑ups.