- Security fixes address CVE-2025-30157 and CVE-2025-31498, including a c-ares upgrade and correcting local reply handling.
- Introduces many features such as async load balancing, dynamic runtime modules, io_uring sockets, QUIC load‑balancing draft, PKCE for OAuth2, extended compression filter controls, and enhanced ext‑proc and transport‑tap capabilities.
- Improves reliability and performance with fixes to HTTP/1 parsing, TCP proxy retry handling, pre‑connect logic, port exhaustion, socket option applications, and crash prevention for malformed EDS clusters.