sigstore-go has a multi-log threshold bypass via single compromised log (CVE-2026-49834) | HOL Guard CVE