CVE-2026-32647: fix buffer over-read/over-write in ngxhttpmp4_module
via integer overflow, off-by-one boundary checks, and zero sync sample
validation in stss atom
CVE-2026-27651: fix NULL pointer dereference in ngxmailauthhttpmodule
when using CRAM-MD5 or APOP authentication with Auth-Wait response