html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding (CVE-2026-66843) | HOL Guard CVE