Rack's multipart byte range processing allows denial of service via excessive overlapping ranges (CVE-2026-34826) | HOL Guard CVE