xmldom: XML injection through unvalidated DocumentType serialization (CVE-2026-41674) | HOL Guard CVE