- Fixed multiple critical CVEs affecting gRPC, OAuth2, TLS, JSON, DNS, HTTP/3 and other components
- Updated wasm runtime to a newer wasmtime version to address a CVE
- Disabled the contrib Envoy.network.connection_balance.dlb extension in Bazel builds due to upstream breakage