go.qbee.io/transport: Symlink-chain path traversal in tar extraction (one level outside destination) (CVE-2026-55828) | HOL Guard CVE