Apache Airflow: Session cookie silently overrides explicit Authorization bearer header, enabling session fixation (CVE-2026-82355) | HOL Guard CVE