ash_authentication_oauth2_server treats an empty resolved secret as valid, opening the gated Dynamic Client Registration endpoint (CVE-2026-82758) | HOL Guard CVE