HTTPX2: Multipart part header injection via unvalidated file Content-Type and custom headers (CVE-2026-84379) | HOL Guard CVE