Apache Airflow AWS Auth Manager - Host Header Injection Leading to SAML Authentication Bypass (CVE-2026-25604) | HOL Guard CVE