Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection (CVE-2026-50630) | HOL Guard CVE