- Fixed multiple security vulnerabilities (CVE‑2026‑27977‑27980, CVE‑2026‑29057) and prevented request smuggling and unsafe websocket connections.
- Resolved hanging streaming fetch calls, ensured maxPostponedStateSize compliance, and applied server‑action transforms to node modules in route handlers.
- Added LRU disk cache and configurable maximumDiskCacheSize to next/image.