9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF (CVE-2026-55641) | HOL Guard CVE