Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...} (CVE-2026-56154) | HOL Guard CVE