9Router: Authentication Bypass in Public LLM API via Spoofable X-9r-Real-Ip Header (CVE-2026-56681) | HOL Guard CVE