RabbitMQ Java client: Unvalidated Class.forName in JSON-RPC ProcedureDescription enables arbitrary class loading (CVE-2026-63337) | HOL Guard CVE