Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication (CVE-2026-28699) | HOL Guard CVE