@fastify/auth vulnerable to Authorization Bypass via order-dependent evaluation of composed auth (CVE-2026-92087) | HOL Guard CVE