HTTP/2 header field values containing CR, LF or NUL are passed to the application unvalidated in Bandit (CVE-2026-75484) | HOL Guard CVE