`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matching (CVE-2026-15806) | HOL Guard CVE