sigstore-go has a multi-log threshold bypass via single compromised log in github.com/sigstore/sigstore-go (CVE-2026-49834) | HOL Guard CVE