Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy Evaluation in fast-xml-parser (CVE-2026-33349) | HOL Guard CVE