@utcp/http: SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol (CVE-2026-45366) | HOL Guard CVE