LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime) (CVE-2026-45357) | HOL Guard CVE