Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication (CVE-2026-92609) | HOL Guard CVE