Gitea runner registration-token GET endpoint performs a write under a read-only token scope (CVE-2026-24059) | HOL Guard CVE