CRLF injection in Laravel's default email rule enables SMTP smuggling and spoofed-mail relay (CVE-2026-48019) | HOL Guard CVE