Acm-search-v2-api-rhel9: search-v2-api: authentication bypass on /federated via upgrade: websocket header spoofing (CVE-2026-71467) | HOL Guard CVE