Symfony UX: XSS in symfony/ux-icons via unsanitized SVG content in local files and Iconify on-demand responses (CVE-2026-55877) | HOL Guard CVE