TarsWeb through 3.0.14 Authentication Bypass via Spoofed X-Forwarded-For and uid Parameter (CVE-2026-80349) | HOL Guard CVE