MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood (CVE-2026-67430) | HOL Guard CVE