GitHub CLI has an incorrect authorization header in API requests to TUF repository mirrors via gh attestation, gh release verify, and gh release verify-asset commands in github.com/cli/cli
{
"review_status": "UNREVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2026-5271"
}