Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.
https://github.com/go-gitea/gitea/security/advisories/GHSA-cc8w-r4qh-3v65
https://github.com/go-gitea/gitea/releases/tag/v1.26.2