ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components (CVE-2026-55671) | HOL Guard CVE