Gitea does not properly verify authorization when canceling scheduled auto-merges via the web interface in code.gitea.io/gitea
{ "url": "https://pkg.go.dev/vuln/GO-2026-4366", "review_status": "UNREVIEWED" }
"https://vuln.go.dev/ID/GO-2026-4366.json"