Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification (CVE-2026-28802) | HOL Guard CVE