PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling (CVE-2026-48979) | HOL Guard CVE