Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout (CVE-2026-59219) | HOL Guard CVE