MariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URL (CVE-2026-44170) | HOL Guard CVE