RabbitMQ: Non-RFC-conformant cookie name when clearing the auth-mechanism preference (CVE-2026-67234) | HOL Guard CVE