CVE-2026-3857: CSRF in GitLab Allows Unauthenticated GraphQL | NextGuard