Http4s: ResourceService and Webjar Service path escape via percent-encoded separators (CVE-2026-69201) | HOL Guard CVE