Apache XMLSchema: Denial of service through deeply nested schema structures (CVE-2026-102496) | HOL Guard CVE