MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal (CVE-2026-52869) | HOL Guard CVE