- Patched multiple CVEs (nghttp2, undici, integrity check bypass, Wasm export name injection) spanning high to low severity
- Updated nghttp2 to v1.57.0 and undici to v5.26.3, added tamper‑proof integrity check and fixed export‑name code injection
- No functional or API changes; release focuses solely on security and dependency updates