Highlights
Auth Bypass: 1 prior fix. Scrutinize any change in this area.
conn.go: most-fixed (1 issue). Treat as high-risk during review.
1 high-severity fix in this history; regressions here are high-impact.
Recurring patterns
The bug types that recur here, drawn from past fixes, not open vulnerabilities.
Auth Bypass: A synchronization gap in the connection handshake protocol allowed clients to execute operations or transmit application payloads before the OnConnect validation callback had fully completed and authorized the session. This effectively bypassed connection guards during a critical timing window.