See here for a changelog: http://nginx.org/en/CHANGES-1.26 Fixes the following security issue: CVE-2025-23419: Security: insufficient check in virtual servers handling with TLSv1.3 SNI allowed to reuse SSL sessions in a different virtual server, to bypass client SSL certificates verification https://www.cve.org/CVERecord?id=CVE-2025-23419 Signed-off-by: Waldemar Brodkorb <wbx@openadk.org> Signed-off-by: Peter Korsgaard <peter@korsgaard.com>