Warpgate: x-warpgate-username Header Not Stripped from Client Requests Enables Identity Spoofing to WebSocket Backend Targets (CVE-2026-63329) | HOL Guard CVE