Static Web Server: Authentication bypass on /metrics endpoint when --basic-auth is enabled (CVE-2026-75601) | HOL Guard CVE