Spring Authorization Server Default Consent Page is vulnerable to Cross-Site Scripting (XSS) (CVE-2026-59316) | HOL Guard CVE