Caddy: FastCGI header normalization bypass in `forward_auth copy_headers` (CVE-2026-52845) | HOL Guard CVE