Mirror-registry: quay: insecure direct object reference in blobupload (CVE-2026-32589) | HOL Guard CVE