OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing (CVE-2026-40575) | HOL Guard CVE