HTTPX2: Streaming response decompression does not bound peak memory (decompression amplification) (CVE-2026-84382) | HOL Guard CVE