Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute (CVE-2026-76781) | HOL Guard CVE