datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default) (CVE-2026-54690) | HOL Guard CVE