libgit2: HTTP transport can leak credentials to an offsite redirect target (CVE-2026-53586) | HOL Guard CVE