SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policy (CVE-2026-77298) | HOL Guard CVE