Medplum - Exposure of OAuth client secret via dynamic registration endpoint in self-hosted configurations (CVE-2026-44506) | HOL Guard CVE