i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names (CVE-2026-48714) | HOL Guard CVE