Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured (CVE-2026-75973) | HOL Guard CVE