scim_proto and kanidm_proto have an authenticated process abort via SCIM filter stack exhaustion (CVE-2026-46689) | HOL Guard CVE