MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches (CVE-2026-77261) | HOL Guard CVE