webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints (CVE-2026-14620) | HOL Guard CVE