- Multiple security fixes targeting a range of CVEs, including authz crashes, OAuth2 vulnerabilities, TLS SAN bypass, and HTTP/3 denial‑of‑service issues.
- Disabled the contrib extension `envoy.network.connection_balance.dlb` in all builds due to upstream source breakage and updated the wasm dependency to resolve a related CVE.
- Updated documentation, release notes, and Docker image tags for the v1.37.5 release.