_GitLab Plugin allows cross-channel post injection and phishing via missing channel permission checks in issue API endpoints_ (CVE-2026-16049) | HOL Guard CVE