djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack) (CVE-2026-61592) | HOL Guard CVE