Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack (CVE-2025-49506) | HOL Guard CVE