- Patched multiple high‑severity CVEs (2026‑32595, 2026‑32305, 2026‑32695) and made basic‑auth timing constant for security.
- Added new features: OTel‑compatible trace context attributes in access logs, maxResponseBodySize option for HTTP provider, and fragmented TLS client‑hello support.
- Fixed a range of bugs across K8s gateway API, ingress routing, NGINX SSL verification, logging, and updated documentation (security note, regex examples, vulnerability guidelines, etc.).