lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS (CVE-2026-92106) | HOL Guard CVE