Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl (CVE-2026-91852) | HOL Guard CVE