axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy` (CVE-2026-44494) | HOL Guard CVE