CloudTAK: Authenticated full-read SSRF in the /api/esri* routes — user-controlled URL fetched with no IP-classification guard (CVE-2026-55177) | HOL Guard CVE