Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption (CVE-2026-47775) | HOL Guard CVE