Strapi users-permissions - JWT Algorithm Confusion via Missing Algorithm Configuration (CVE-2026-57997) | HOL Guard CVE