lettre has TLS hostname verification disabled when using Boring TLS backend (CVE-2026-46428) | HOL Guard CVE