Unencoded HTML Outputs in Spring Security May Allow Cross-Site Scripting (CVE-2026-41003) | HOL Guard CVE