Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing (CVE-2026-50631) | HOL Guard CVE