Apache WSS4J: UsernameToken replay protection bypassed by re-encoding the Nonce (CVE-2026-92899) | HOL Guard CVE