MapServer: Reflected XSS in OpenLayers HTML Output via `HTTP_X_FORWARDED_HOST` (CVE-2026-54355) | HOL Guard CVE