Discourse: Block post iframes whose encoded userinfo bypasses the allowed_iframes allowlist (CVE-2026-91134) | HOL Guard CVE