- Added URLPattern request matcher, new TLS automate‑names option, expected‑underscore/dot header controls, and HTTP/3 support on low‑MTU links.
- Implemented security hardening: default 16 KiB header limit, 1 min idle read/write timeouts, stricter config validation, and multiple CVE‑related fixes.
- Breaking changes include requiring Go 1.26, reduced default header size, new idle timeout defaults, and altered client‑auth inheritance behavior.