Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration (CVE-2026-41006) | HOL Guard CVE