Apache APISIX: JWT Algorithm Confusion allows authentication bypass (CVE-2026-39999) | HOL Guard CVE