SECURITY UPDATE: heap buffer overflow in ngxhttprewrite_module when an
unnamed PCRE capture group with '?' in the replacement is followed by
another rewrite, if, or set directive
debian/patches/CVE-2026-42945.patch: clear isargs flag at the start
of ngxhttpscriptregexendcode() in src/http/ngxhttpscript.c so
it does not leak into subsequent script code on the same engine.