Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup (CVE-2026-39998) | HOL Guard CVE