Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
https://github.com/go-gitea/gitea/releases/tag/v1.25.5
https://github.com/go-gitea/gitea/pull/36836