Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control (CVE-2026-65927) | HOL Guard CVE