Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue (CVE-2026-76986) | HOL Guard CVE