golang.org/x/image/tiff has excessive resource consumption in PackBits decompression (CVE-2026-46599) | HOL Guard CVE