Warpgate: Reflected XSS in SSO return endpoint via attacker-controlled next parameter (CVE-2026-58491) | HOL Guard CVE