Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets
ID: 454532bd-d8b6-5237-b4b4-149ccd203235
STIX ID: report--454532bd-d8b6-5237-b4b4-149ccd203235
Feed Name: Security Affairs
Sysdig and security researcher reports reveal CVE-2026-20896, a critical (CVSS 9.8) authentication-bypass in Gitea official Docker images (<=1.26.2) caused by REVERSE_PROXY_TRUSTED_PROXIES being set to '*', allowing anyone who can reach the HTTP port to impersonate users via the X-WEBAUTH-USER header; the flaw was observed exploited in the wild shortly after disclosure and fixed in 1.26.3/1.26.4 — administrators should immediately update exposed instances to prevent repository and secret exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
