Jenkins LDAP Plugin deserializes data from LDAP referrals without validation (CVE-2026-48917) | HOL Guard CVE