- Fixed CVE‑2026‑29785 and CVE‑2026‑27889 affecting leafnode compression and WebSockets
- Resolved several panic‑inducing bugs: leafnode subscription handling, 64‑bit payload parsing, compressed frame rejection, Origin header scheme validation, CLOSE frame length/status checks, compressor state reset, and empty compressed buf...
- Updated Go to 1.25.8, refreshed crypto/sys/time dependencies, and improved graceful handling of failed connection upgrades