Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications (CVE-2026-28779) | HOL Guard CVE