@fastify/jwt vulnerable to authorization bypass via global secret overriding the per-request key (CVE-2026-18500) | HOL Guard CVE