- Fixed CVE-2026-54763 and CVE-2026-54764 security vulnerabilities
- Added configurable max request header size and an option to strip request headers containing underscores
- Updated documentation for HTTP/2 header memory exhaustion and maxHeaderBytes settings