@fastify/http-proxy vulnerable to prefix escape via backslash dot-segments (CVE-2026-85124) | HOL Guard CVE