RabbitMQ: Plaintext username:password stored in an insecure cookie after successful POST /login (CVE-2026-67236) | HOL Guard CVE