HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis (CVE-2026-46391) | HOL Guard CVE