httpd mod_auth directory protection bypassed by a doubled slash in the request path (CVE-2026-66835) | HOL Guard CVE