Gitea: Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes (CVE-2026-24791) | HOL Guard CVE