Chartbrew: SQL Injection via Missing Backslash Escaping in ClickHouse Variable Substitution (CVE-2026-65980) | HOL Guard CVE