Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references (CVE-2026-73491) | HOL Guard CVE