Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens (CVE-2026-28744) | HOL Guard CVE