Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (CVE-2026-49853) | HOL Guard CVE