CVE-2026-35042: fast-jwt accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) — Zero Day Monitor