Weblate: Restricted-component change history leaked to non-member project users through the nested `GET /api/projects/{slug}/changes/` endpoint (CVE-2026-62249) | HOL Guard CVE