Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
https://github.com/go-gitea/gitea/security/advisories/GHSA-9r5x-wg6m-x2rc
https://github.com/go-gitea/gitea/releases/tag/v1.26.2