CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injection (CVE-2026-48596) | HOL Guard CVE