Cross-tenant database retargeting via dot/NUL injection in namespace strings in the PHP Driver (CVE-2026-81525) | HOL Guard CVE