Microsoft Security Response Center Follow CVE-2026-43966 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43966 msrc.microsoft.com