Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument (CVE-2026-47240) | HOL Guard CVE