API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate (CVE-2026-49858) | HOL Guard CVE