Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68941.json"