*) Security: a heap memory buffer overflow might occur in a worker process under certain configurations when using HTTP/3 with OpenSSL 3.5.0 and earlier (CVE-2026-90439). Thanks to Banny Liao.
*) Change: now the QUIC transport parameters extension received in an SSL connection is always ignored.
*) Bugfix: binary upgrade refused to work if the control API socket was specified and the new nginx executable was built with the ngx_http_perl_module.
*) Bugfix: an error while evaluating a predicate in a predicate location was ignored and the predicate was treated as false.
*) Bugfix: an error during a nested location lookup might be ignored if locations given by regular expressions or predicates were configured at the current level.
*) Bugfix: a segmentation fault might occur while reading configuration if the "geo" directive with the "ranges" parameter was used and the corresponding binary base file was corrupted.