mint has potential CRLF injection in its HTTP request line via unvalidated `method`/`target` (CVE-2026-48861) | HOL Guard CVE