SECURITY UPDATE: Heap buffer overflow in ngx_http_rewrite_module via
overlapping PCRE captures in replacement strings
debian/patches/CVE-2026-9256.patch: recompute buffer length per
capture (including escaping) in ngx_http_script_regex_start_code
to prevent buffer overrun when redirect parameter is used or
arguments appear in the rewrite replacement string