- Throw on InternalWorker usage when permission model is enabled (CVE‑2025‑23083)
- Fix HTTP/2 memory leak on premature close and ERR_PROTO (CVE‑2025‑23085)
- Patch path traversal in normalize() on Windows and update undici to v6.21.1 (CVE‑2025‑23084, CVE‑2025‑22150)