RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698) (CVE-2026-50105) | HOL Guard CVE