jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used (CVE-2026-6657) | HOL Guard CVE