Mistune: XSS via percent-encoded javascript URI bypass in safe_url() (CVE-2026-59923) | HOL Guard CVE