HIGH7.5npmGHSA-wxqq-gcq8-c443· CVE-2026-50272dd-trace-js: Improper parsing of W3C baggage headers may lead to DoSModified: 9/10/2026