PrivateBin: Reflected JSON injection in backend responses via unescaped REQUEST_URI (CVE-2026-55891) | HOL Guard CVE