AshAdmin ships a hardcoded CSP nonce, allowing nonce-based CSP bypass (CVE-2026-81852) | HOL Guard CVE