Dragonfly Manager OAuth provider client_secret disclosure via unauthenticated GET /api/v1/oauth (CVE-2026-49254) | HOL Guard CVE