- Fixed multiple HTTP/2 security issues (CVE‑2026‑47774, CVE‑2026‑27135) and hardened OAuth2 HMAC verification and token cookie handling
- Added stats library features: evictable metrics removal and per‑scope stat limits applied during periodic flush
- Fixed shutdown race on ADS stream in load reporting