rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix (CVE-2026-85396) | HOL Guard CVE