logo

Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets

ID: 454532bd-d8b6-5237-b4b4-149ccd203235

STIX ID: report--454532bd-d8b6-5237-b4b4-149ccd203235

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-07-07

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

Sysdig and security researcher reports reveal CVE-2026-20896, a critical (CVSS 9.8) authentication-bypass in Gitea official Docker images (<=1.26.2) caused by REVERSE_PROXY_TRUSTED_PROXIES being set to '*', allowing anyone who can reach the HTTP port to impersonate users via the X-WEBAUTH-USER header; the flaw was observed exploited in the wild shortly after disclosure and fixed in 1.26.3/1.26.4 — administrators should immediately update exposed instances to prevent repository and secret exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.