Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. (CVE-2026-22741) | HOL Guard CVE