In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization (CVE-2026-41731) | HOL Guard CVE