Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy (CVE-2026-57941) | HOL Guard CVE