Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader (CVE-2026-87996) | HOL Guard CVE