backpack/crud: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth) (CVE-2026-54182) | HOL Guard CVE