eventsource-encoder vulnerable to SSE event injection via unsanitized `event` and `id` fields (CVE-2026-44214) | HOL Guard CVE