oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (CVE-2026-48978) | HOL Guard CVE