- Security hardening: restrict SFTP for normal users, fix SSRF via reverse tunnel, filter macOS DYLD variables, bump golang.org/x/crypto to address CVE‑2023‑48795, and add lock/MFA/Webauthn protections.
- New functionality: add IAM join method support, raise minimum Teleport Connect macOS version to 10.15, and update jose2go to v1.5.1.
- Various bug fixes: resolve websocket upgrade failures, include lock expiration in audit events, correct session upload URLs, improve MFA error responses, and prevent hangs when joining nonexistent SSH sessions.