FastMCP OpenAPI Provider has an SSRF & Path Traversal Vulnerability (CVE-2026-32871) | HOL Guard CVE