OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS) (CVE-2026-45696) | HOL Guard CVE