MCP Registry has open redirect via protocol-relative path in trailing-slash middleware (CVE-2026-44427) | HOL Guard CVE