Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation (CVE-2026-4874) | HOL Guard CVE