DjangoCRM: Hardcoded Django SECRET_KEY Enables Session and CSRF Token Forgery (CVE-2026-71238) | HOL Guard CVE