Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT (CVE-2026-76187) | HOL Guard CVE