Spring Security Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS) (CVE-2026-47877) | HOL Guard CVE