Apache Roller: XML external entity processing in OPML bookmark import (CVE-2026-82386) | HOL Guard CVE