Jenkins Credentials Binding Plugin does not properly sanitize file names for file and zip file credentials (CVE-2026-48922) | HOL Guard CVE