NATS Server: `no_auth_user` pre-CONNECT fast path bypasses user connection restrictions (CVE-2026-58211) | HOL Guard CVE