TeamDavid: Header Injection through request body in link storing functionality (CVE-2026-54199) | HOL Guard CVE