Tesla has CRLF injection in request `Content-Type` header via `add_content_type_param` (CVE-2026-48596) | HOL Guard CVE