Symfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing (CVE-2026-45064) | HOL Guard CVE