Heap buffer overflow via wrapped size check during SASL username canonicalization in MongoDB C Driver (CVE-2026-88035) | HOL Guard CVE