PyJWT: Non-canonical signature segments enable raw-token revocation bypass (CVE-2026-102269) | HOL Guard CVE