Apache XMLSchema: Denial of service through unbounded recursion when resolving schema imports and includes (CVE-2026-102495) | HOL Guard CVE