Dgraph: DQL Injection via unvalidated regexp filter argument in GraphQL query rewriter (CVE-2026-63637) | HOL Guard CVE