Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf protection mechanisms (CVE-2026-91928) | HOL Guard CVE