Magistrala < 1.0.0 SQL Injection via format Parameter in Reader API (CVE-2026-82028) | HOL Guard CVE