fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization (CVE-2026-86818) | HOL Guard CVE