- Fixed critical CVE‑2026‑54763 and CVE‑2026‑54764 and added HTTP/2 header memory exhaustion security documentation.
- Resolved numerous bugs across ACME, Kubernetes EndpointSlice handling, middleware (CORS, RequestHeaderModifier, forward‑auth), TLS certificate selection, and WebSocket h2c upgrades.
- Introduced new features such as an option to remove request headers with underscores, configurable max request header size, added missing Gateway API features, updated provider list, and aligned Helm chart documentation.