Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider (CVE-2026-22746) | HOL Guard CVE