social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing (CVE-2026-57178) | HOL Guard CVE