Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) (CVE-2026-54481) | HOL Guard CVE