Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service (CVE-2026-68749) | HOL Guard CVE