canto-saas-api: OAuth credentials exposed in URL query string and exception messages (CVE-2026-55375) | HOL Guard CVE