Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base (CVE-2026-84376) | HOL Guard CVE