LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. (CVE-2026-50635) | HOL Guard CVE