Apache PLC4X, Apache PLC4X: Pre-authentication resource exhaustion in the OPC UA driver and the Java SPI parser (CVE-2026-102509) | HOL Guard CVE