New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging (CVE-2026-64868) | HOL Guard CVE