Http4s: FollowRedirect middleware leaks credentials over https->http same-authority redirect (CVE-2026-69212) | HOL Guard CVE