Apache InLong: SQL Injection via Unvalidated MyBatis Dollar-Sign Interpolation in AuditAlertRuleService (CVE-2026-63039) | HOL Guard CVE