Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability (CVE-2026-41608) | HOL Guard CVE