Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot (CVE-2026-53500) | HOL Guard CVE