Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching (CVE-2026-59223) | HOL Guard CVE