Apache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flow (CVE-2026-57817) | HOL Guard CVE