nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.) (CVE-2026-47723) | HOL Guard CVE