Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier (CVE-2026-50629) | HOL Guard CVE