OpenEXR: Out-of-bounds read in `IDManifest::init()` during prefix expansion (CVE-2026-42216) | HOL Guard CVE