path-to-regexp vulnerable to Denial of Service via sequential optional groups (CVE-2026-4926) | HOL Guard CVE