Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login (CVE-2026-48589) | HOL Guard CVE