CVE-2026-32148: Lockfile checksums not verified in Hex allows dependency integrity bypass — Zero Day Monitor