Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header (CVE-2026-48061) | HOL Guard CVE