Jenkins Active Directory Plugin deserializes data from LDAP referrals without validation (CVE-2026-48919) | HOL Guard CVE