BerriAI litellm M2M JWT user_api_key_auth.py improper authorization (CVE-2026-12771) | HOL Guard CVE