Django vulnerable to ASGI header spoofing via underscore/hyphen conflation (CVE-2026-3902) | HOL Guard CVE