- Patched high‑severity CVEs across http2, http, https, dns, permission, and zlib modules, including header memory handling and identity checks.
- Added runtime safeguards such as rejecting requests exceeding max header count and enforcing filesystem write permissions for trace events.
- Updated core dependencies: llhttp to 9.4.3 and undici to 6.28.0.