Rack's greedy multipart boundary parsing can cause parser differentials and WAF bypass. (CVE-2026-26961) | HOL Guard CVE