Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout (CVE-2026-87011) | HOL Guard CVE