jackson-databind: quadratic forward-reference completion in Collection and Map deserializers (CVE-2026-91777) | HOL Guard CVE