Apache CXF's WS-Transfer module has an insecure XML parser configuration (CVE-2026-44618) | HOL Guard CVE