- Patched multiple CVEs (2026‑26998, 2026‑26999, 2026‑29054) to address security vulnerabilities.
- Fixed case‑sensitivity handling of X‑Forwarded‑For headers in middleware and added configurable maxResponseBodySize to the forwardAuth middleware.
- Improved TLS handshake error handling in the server component.