In Spring for Apache Pulsar, overly broad trusted-package matching in header mapper exposes JDK classes to deserialization (CVE-2026-41732) | HOL Guard CVE