- Applied upstream security patches for numerous CVEs covering authz crashes, OAuth2 padding oracle, TLS SAN bypass, HTTP/3 QPACK DoS, and other vulnerabilities.
- Disabled the contrib extension `envoy.network.connection_balance.dlb` in Bazel builds due to a source‑archive breakage.
- Updated documentation links and Docker image tags for the v1.36.9 release.