Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']` (CVE-2026-46637) | HOL Guard CVE