Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalation (CVE-2026-54330) | HOL Guard CVE