Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout (CVE-2026-48726) | HOL Guard CVE