Gitea: OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation) in gitea.dev
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2026-6079" }
"https://vuln.go.dev/ID/GO-2026-6079.json"