Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification (CVE-2026-47774) | HOL Guard CVE