- Patch critical CVE-2023-6337 to stop denial-of-service via memory exhaustion on large HTTP requests.
- Enterprise change: POSTs to /identity/entity/merge are now always forwarded from standby nodes to the active node.
- Fix multiple bugs including agent logging format, sys/leader deadlock, core init timeout, UI redirect handling, replication payload, and KV v2 read‑only JSON view.