inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs (CVE-2026-59925) | HOL Guard CVE