Volsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml via text/template without escaping allows yaml injection into subscription (CVE-2026-18874) | HOL Guard CVE