protobufjs: Code injection through bytes field defaults in generated toObject code (CVE-2026-44293) | HOL Guard CVE