SECURITY UPDATE: Heap buffer overflow in ngx_http_rewrite_module via
PCRE unnamed captures with question mark in replacement strings
debian/patches/CVE-2026-42945.patch: clear e->is_args in
ngx_http_script_regex_end_code to prevent buffer overrun when
rewrite directive is followed by set or if with PCRE captures