Libevent: HTTP header handling bugs create risk of access control bypass. (CVE-2026-63385) | HOL Guard CVE