Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry (CVE-2026-50634) | HOL Guard CVE