Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk) (CVE-2026-48090) | HOL Guard CVE