Unsafe Java deserialization in DefaultExecutionContextSerializer without class allowlist (CVE-2026-47878) | HOL Guard CVE