Connection-option injection via unescaped settings in the canonical MongoDB URL builder (CVE-2026-81529) | HOL Guard CVE