Claircore: Unauthenticated attackers can submit manifests with URIs pointing to internal services or cloud metadata endpoints (CVE-2026-10517) | HOL Guard CVE