Gitea OAuth2 PKCE S256 challenges are not enforced during token exchange (CVE-2026-26247) | HOL Guard CVE