xmldom: XML node injection through unvalidated processing instruction serialization (CVE-2026-41675) | HOL Guard CVE