Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS (CVE-2026-45756) | HOL Guard CVE