Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.
https://github.com/go-gitea/gitea/security/advisories/GHSA-8629-vc8r-5p58
https://github.com/go-gitea/gitea/releases/tag/v1.26.2