Spring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter Binding (CVE-2026-41717) | HOL Guard CVE