OpenRGB: insufficient input data checks lead to Denial-of-Service, memory overread and overwrite (CVE-2026-18794) | HOL Guard CVE