Headroom Proxy Treats the Client-Supplied x-headroom-user-id Header as an Authenticated Identity (CVE-2026-77776) | HOL Guard CVE