NATS credentials are exposed in monitoring port via command-line argv (CVE-2026-33247) | HOL Guard CVE