fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names (CVE-2026-25896) | HOL Guard CVE