Boruta: Authenticated atom-exhaustion DoS in BorutaIdentityWeb.UserSettingsController.update/2 (CVE-2026-49249) | HOL Guard CVE