CVE-2026-42533: a pre-auth heap buffer overflow in nginx's HTTP script engine. We reproduced the crash on 1.31.2 and verified the 1.31.3 fix end to end.