fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit) (CVE-2026-26278) | HOL Guard CVE