Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` (from huntr) (CVE-2026-40110) | HOL Guard CVE