Fixes five low-severity CVEs CVE-2026-6873: Signed cookie salt namespace collision CVE-2026-7666: Potential unencrypted email transmission via STARTTLS in the SMTP backend CVE-2026-8404: Potential exposure of private data via case-sensitive Cache-
0.0.32 (2026-06-04) Speed up partial-boundary scanning for CR/LF-dense part data. 0.0.31 (2026-06-04) Speed up multipart header parsing and callback dispatch. Bound header field name size before validating.
Bug Fixes: CVE-2026-33254: An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default CVE-2026-33257: An attacker can send a web request that causes unlimited memory