PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse (CVE-2026-103001) | HOL Guard CVE