CVE-2026-58443: Gitea: Public-only repository tokens can update private PR head branches

Severity: Critical

CVSS Score: 9.6

Public-only repository tokens can update private PR head branches