CVE-2026-1502 CVE Information CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host. Related Releases CTRL-OS 26.05