Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http (CVE-2026-56853) | HOL Guard CVE