go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git (CVE-2026-45022) | HOL Guard CVE