Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service (CVE-2026-68750) | HOL Guard CVE