XML External Entity (XXE) injection when documenting untrusted XML content (CVE-2026-40991) | HOL Guard CVE