async-http-client: Cookie header not stripped on cross-origin redirect (CVE-2026-45300) | HOL Guard CVE