Security: When using an OpenSSL version without native HTTP/3 support (3.5.0 or earlier), if the default server for the address that accepted a regular HTTPS request also used HTTP/3 (the listen directive with the quic parameter, possibly on a different port), while a server block without HTTP/3 was selected by domain name (SNI), limited worker process memory corruption or a worker process crash could occur (CVE-2026-90439); the fix was ported from nginx 1.31.6.