Auth0 Symfony: Bearer Token Accepted via URL Query Parameter in Auth0 Symfony SDK (CVE-2026-50157) | HOL Guard CVE