Gitea Composer package source links use insufficient permission checks (CVE-2026-27771) | HOL Guard CVE