PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys (CVE-2026-48523) | HOL Guard CVE