@acastellon/auth: Authentication bypass via spoofable headers in validateToken() (CVE-2026-58399) | HOL Guard CVE