@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register` (CVE-2026-58271) | HOL Guard CVE