pip would incorrectly handle doubly-encoded package URLs from indexes (CVE-2026-13346) | HOL Guard CVE