Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html (CVE-2026-25681) | HOL Guard CVE