- Fixed improper handling of URI Subject Alternative Names to prevent certificate verification bypass (CVE‑2021‑44531).
- Patched SAN string injection and multi‑value Relative Distinguished Name handling, closing hostname verification bypasses (CVE‑2021‑44532, CVE‑2021‑44533).
- Mitigated prototype pollution in console.table by using a null prototype (CVE‑2022‑21824).