Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057) (CVE-2026-85229) | HOL Guard CVE