Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header (CVE-2026-93682) | HOL Guard CVE