fast-uri vulnerable to host confusion via percent-encoded scheme normalization (CVE-2026-76172) | HOL Guard CVE