- - Patched multiple critical CVEs (2026‑40912, 2026‑39858, 2026‑35051, 2026‑41263, 2026‑41174); see migration guide for details.
- - Fixed several middleware and authentication issues: corrected basic auth secret handling, trustForwardHeader behavior, log consistency, removal of unsafe X‑headers, request URL sanitization, and allowCrossNamespace handling in CRDs.