Rack::Sendfile header-based X-Accel-Mapping regex injection enables unauthorized X-Accel-Redirect (CVE-2026-34830) | HOL Guard CVE