SECURITY UPDATE: XSS via unsanitized request URI in PHP-FPM status page
debian/patches/CVE-2026-6735.patch: escape requesturi with HTML
entities in fpmstatushandlerequest() for HTML/XML output formats,
and fix querystring escape flags in sapi/fpm/fpm/fpmstatus.c