CVE-2026-58443: code.gitea.io/gitea: Gitea: Unauthorized update of private pull request branches via public-only tokens

Severity: Critical

CVSS Score: 9.6

Public-only repository tokens can update private PR head branches