Http4s: CookieJar middleware matches by substring, leaking cookies cross-origin (CVE-2026-69215) | HOL Guard CVE