- Patched CVE-2026-54763, CVE-2026-54764, and CVE-2026-54765 and fixed nondeterministic TLS certificate selection on shared SANs.
- Added server options to drop request headers with underscores and to configure the maximum request header size; numerous bug fixes across ACME, ingress, gateway API, middleware, and Kubernetes components.
- Improved and clarified documentation, Helm chart values, and authentication header handling, and updated CRD reference links.