`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes (CVE-2026-49825) | HOL Guard CVE