Hackers exploit critical auth bypass in Gitea Docker image
ID: b33a8447-f461-5e20-be80-43201cc41b47
STIX ID: report--b33a8447-f461-5e20-be80-43201cc41b47
Feed Name: Bleeping Computer
A critical authentication-bypass vulnerability (CVE-2026-20896) in Gitea's official Docker image—caused by the default REVERSE_PROXY_TRUSTED_PROXIES='*' configuration trusting X-WEBAUTH-USER headers from any client—allows unauthenticated attackers to impersonate arbitrary users (including admins). Exploitation was observed in the wild shortly before disclosure, around 6,200 Gitea instances are publicly reachable, and Gitea has released patched versions (1.26.3/1.26.4) with guidance to upgrade or restrict trusted proxy IPs as mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
