WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode (CVE-2026-31892) | HOL Guard CVE