Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass) (CVE-2026-47778) | HOL Guard CVE