Dulwich doesn't sanitize commit subjects in `porcelain.format_patch` (CVE-2026-47712) | HOL Guard CVE