FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files (CVE-2026-45062) | HOL Guard CVE