Unbound 1.26.1 fixes nine CVEs; nginx 1.31.6 fixes one this build never compiled
Unbound 1.26.1 was published at 08:22 UTC and was serving here at 11:48 UTC. It consolidates nine CVEs and ships a Changelog that mentions none of them, so the mapping from identifier to code had to be recovered by diffing the trees. nginx 1.31.6 carries CVE-2026-90439, whose fix is confined to the OpenSSL compatibility layer - code a BoringSSL build does not compile.