Quarkus authorization bypass via semicolon path normalization inconsistency (CVE-2026-39852) | HOL Guard CVE