In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header (CVE-2026-41726) | HOL Guard CVE