Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL (CVE-2026-54072) | HOL Guard CVE