Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets (CVE-2026-88001) | HOL Guard CVE