xmldom: XML node injection through unvalidated comment serialization (CVE-2026-41672) | HOL Guard CVE