Excessive memory allocation when decoding malicious SFNT in golang.org/x/image (CVE-2026-33812) | HOL Guard CVE