A security-focused maintenance release addresses disclosed Go vulnerabilities and improves proxy connection-pool performance. It also adds the forward plugin's max_idle_conns parameter, which defaults to 0 for an unbounded pool.
Action needed (1)
securityhighCVE-2025-68119 fix
The release also addresses CVE-2025-68119, which affects the stated Go versions.
Check if affected (1)
securitycriticalGo security vulnerability fixes
Applicability is not stated in the release notes.
This release addresses vulnerabilities affecting Go versions before
Go 1.and25. 6 Go 1.: CVE-2025-61728, CVE-2025-61726, CVE-2025-68121, and CVE-2025-61731.24. 12