SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header (CVE-2026-15583) | HOL Guard CVE